Severity
7.5HIGH
EPSS
5.9%
top 9.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24
Latest updateMay 14

Description

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Ubuntujasper< 1.900.1-14ubuntu3.2

Also affects: Enterprise Linux 6.0, 7.0

🔴Vulnerability Details

4
GHSA
GHSA-vv3q-8xfg-h2jp: Heap-based buffer overflow in the jp2_decode function in JasPer 12022-05-14
OSV
jasper vulnerabilities2015-01-26
CVEList
CVE-2014-8138: Heap-based buffer overflow in the jp2_decode function in JasPer 12014-12-24
OSV
CVE-2014-8138: Heap-based buffer overflow in the jp2_decode function in JasPer 12014-12-24

📋Vendor Advisories

3
Ubuntu
Ghostscript vulnerabilities2015-01-26
Ubuntu
JasPer vulnerabilities2015-01-26
Red Hat
jasper: heap overflow in jp2_decode() (oCERT-2014-012)2014-12-18

💬Community

5
Bugzilla
CVE-2014-8138 CVE-2014-8137 jasper: various flaws [epel-5]2014-12-18
Bugzilla
CVE-2014-8138 CVE-2014-8137 jasper: various flaws [fedora-all]2014-12-18
Bugzilla
CVE-2014-8138 CVE-2014-8137 mingw-jasper: various flaws [epel-7]2014-12-18
Bugzilla
CVE-2014-8138 CVE-2014-8137 mingw-jasper: various flaws [fedora-all]2014-12-18
Bugzilla
CVE-2014-8138 jasper: heap overflow in jp2_decode() (oCERT-2014-012)2014-12-11