CVE-2013-4289: Buffer Overflow
Published Apr 18, 2014
·Updated
Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow.
Affected Software
4 affected components
uclouvain openjpeg<=1.5.1
uclouvain openjpeg=1.3
uclouvain openjpeg=1.4
uclouvain openjpeg=1.5
Event History
Apr 18, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4289?
CVE-2013-4289 is considered a critical vulnerability due to its potential to cause heap-based buffer overflow, allowing remote attackers to exploit it.
2
How do I fix CVE-2013-4289?
To fix CVE-2013-4289, upgrade OpenJPEG to version 1.5.2 or later.
3
What software versions are affected by CVE-2013-4289?
CVE-2013-4289 affects OpenJPEG versions 1.3, 1.4, and 1.5, as well as versions up to and including 1.5.1.
4
Can CVE-2013-4289 be exploited remotely?
Yes, CVE-2013-4289 can be exploited remotely by attackers.
5
What type of vulnerabilities does CVE-2013-4289 involve?
CVE-2013-4289 involves multiple integer overflows that can trigger a heap-based buffer overflow.