MEDIUM · 6.8

CVE-2011-4516

Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corru...

Vulnerability Description

Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Jasper ProjectJasper1.900.1
OracleOutside In Technology8.3.5
CanonicalUbuntu Linux10.04
DebianDebian Linux6.0
FedoraprojectFedora15
SuseLinux Enterprise Desktop11
SuseLinux Enterprise Server11
SuseLinux Enterprise Software Development Kit11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-4516?

CVE-2011-4516 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corru...

How severe is CVE-2011-4516?

CVE-2011-4516 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-4516?

Check the references section above for vendor advisories and patch information. Affected products include: Jasper Project Jasper, Oracle Outside In Technology, Canonical Ubuntu Linux, Debian Debian Linux, Fedoraproject Fedora.