First published: Wed Dec 24 2014(Updated: )
Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Jasper Reports | =1.900.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8138 has a high severity rating due to the potential for remote code execution or denial of service.
To fix CVE-2014-8138, upgrade JasPer to version 1.900.2 or later.
The buffer overflow in CVE-2014-8138 is caused by improper handling of crafted JPEG 2000 files in the jp2_decode function.
CVE-2014-8138 affects JasPer versions up to 1.900.1 and specific versions of Red Hat Enterprise Linux 6.0 and 7.0.
CVE-2014-8138 can enable denial of service attacks or allow attackers to execute arbitrary code remotely.