CVE-2011-4516

Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
jasper_projectjasper
1.900.1
oracleoutside_in_technology
8.3.5
oracleoutside_in_technology
8.3.7
canonicalubuntu_linux
10.04
canonicalubuntu_linux
10.10
canonicalubuntu_linux
11.04
canonicalubuntu_linux
11.10
debiandebian_linux
6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ghostscript
bullseye
9.53.3~dfsg-7+deb11u7
fixed
bullseye (security)
9.53.3~dfsg-7+deb11u8
fixed
bookworm
10.0.0~dfsg-11+deb12u4
fixed
bookworm (security)
10.0.0~dfsg-11+deb12u5
fixed
sid
10.04.0~dfsg-1
fixed
trixie
10.04.0~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ghostscript
oneiric
not-affected
natty
not-affected
maverick
Fixed 8.71.dfsg.2-0ubuntu7.1
released
lucid
Fixed 8.71.dfsg.1-0ubuntu5.4
released
hardy
Fixed 8.61.dfsg.1-1ubuntu3.4
released
jasper
oneiric
Fixed 1.900.1-7ubuntu2.11.10.1
released
natty
Fixed 1.900.1-7ubuntu2.11.04.1
released
maverick
Fixed 1.900.1-7ubuntu0.10.10.1
released
lucid
Fixed 1.900.1-7ubuntu0.10.04.1
released
hardy
ignored
netpbm-free
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
not-affected
References