JasPer Multiple Remote Heap Buffer Overflow Vulnerabilities
BID:50992
Info
JasPer Multiple Remote Heap Buffer Overflow Vulnerabilities
| Bugtraq ID: | 50992 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-4516 CVE-2011-4517 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2011 12:00AM |
| Updated: | Dec 08 2015 10:02PM |
| Credit: | Jonathan Foote of the CERT/CC |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 73.C0.41 Xerox FreeFlow Print Server (FFPS) 73.B3.61 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Symantec Enterprise Vault 9.0.2 Symantec Enterprise Vault 9.0.1 Symantec Enterprise Vault 9.0 Symantec Enterprise Vault 10.0 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux -current RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux 5 Server Oracle Outside In 8.3.7 Oracle Outside In 8.3.5.0 Oracle Outside In 8.3.5.0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Enterprise Linux 4 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 JasPer JasPer 1.900.1 JasPer JasPer 1.900 JasPer JasPer 1.701 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
JasPer Multiple Remote Heap Buffer Overflow Vulnerabilities
JasPer is prone to multiple remote heap-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage these issues to execute arbitrary code in the context of the application that uses the affected library. Failed attacks will cause denial-of-service conditions.
JasPer is prone to multiple remote heap-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage these issues to execute arbitrary code in the context of the application that uses the affected library. Failed attacks will cause denial-of-service conditions.
Exploit / POC
JasPer Multiple Remote Heap Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
JasPer Multiple Remote Heap Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1 x86_64
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2010.1
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva jasper-1.900.1-12.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper-devel-1.900.1-12.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper-static-devel-1.900.1-12.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper1-1.900.1-12.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva jasper-1.900.1-4.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper1-1.900.1-4.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper1-devel-1.900.1-4.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper1-static-devel-1.900.1-4.3mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva jasper-1.900.1-4.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper1-1.900.1-4.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper1-devel-1.900.1-4.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper1-static-devel-1.900.1-4.3mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2010.1
-
Mandriva jasper-1.900.1-12.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper-devel-1.900.1-12.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper-static-devel-1.900.1-12.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper1-1.900.1-12.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva jasper-1.900.1-12.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper-devel-1.900.1-12.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper-static-devel-1.900.1-12.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64jasper1-1.900.1-12.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva jasper-1.900.1-12.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper-devel-1.900.1-12.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper-static-devel-1.900.1-12.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libjasper1-1.900.1-12.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
References
JasPer Multiple Remote Heap Buffer Overflow Vulnerabilities
References:
References: