First published: Thu Oct 02 2008(Updated: )
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Reports | =1.900.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3520 is considered to have a moderate severity due to the potential for integer overflow vulnerabilities that could be exploited by attackers.
To fix CVE-2008-3520, update to a patched version of JasPer that addresses the integer overflow vulnerabilities.
CVE-2008-3520 specifically affects JasPer version 1.900.1.
Exploiting CVE-2008-3520 may lead to memory corruption which can result in arbitrary code execution or crashes.
Users and systems utilizing the vulnerable version of JasPer for processing image files may be affected by CVE-2008-3520.