CVE-2008-3521: Race Condition
Race condition in the jasstreamtmpfile function in libjasper/base/jasstream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file, which causes Jasper to exit. NOTE: this was originally reported as a symlink issue, but this was incorrect. NOTE: some vendors dispute the severity of this issue, but it satisfies CVE's requirements for inclusion.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3521?
CVE-2008-3521 is classified as a denial of service vulnerability that can cause program exit.
How do I fix CVE-2008-3521?
To fix CVE-2008-3521, update to the latest version of JasPer that addresses this vulnerability.
Who is affected by CVE-2008-3521?
Local users running JasPer version 1.900.1 are affected by CVE-2008-3521.
What type of vulnerability is CVE-2008-3521?
CVE-2008-3521 is a race condition vulnerability that leads to denial of service.
What is the potential impact of CVE-2008-3521?
The potential impact of CVE-2008-3521 is an unexpected program exit, causing disruptions.