ubuntu · CVE-2011-4516

Quick triage

Priority: medium Published: 2011-12-14 00:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2011-4516 medium priority: Ubuntu including 3 source packages (ghostscript, jasper, netpbm-free), 18 status rows across 6 suites (hardy, lucid, maverick, natty, oneiric, upstream): not-affected 7, released 7, needs-triage 3, ignored 1.

Description:

Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.

cvelogic Threat Intelligence