Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2015-8751

Published: 17 February 2020

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

Notes

AuthorNote
mdeslaur
already fixed by 01-misc-fixes.patch in Ubuntu
probably a dupe of CVE-2008-3520

Priority

Medium

CVSS 3 base score: 8.8

Status

Package Release Status
jasper
Launchpad, Ubuntu, Debian
upstream Needs triage

precise Not vulnerable

trusty Does not exist
(trusty was not-affected)
wily Not vulnerable

vivid Not vulnerable

ghostscript
Launchpad, Ubuntu, Debian
upstream Needs triage

precise Not vulnerable
(uses system jasper)
trusty Does not exist
(trusty was not-affected [uses system jasper])
wily Not vulnerable
(uses system jasper)
vivid Not vulnerable
(uses system jasper)
netpbm-free
Launchpad, Ubuntu, Debian
upstream Needs triage

precise Not vulnerable
(code not present)
trusty Does not exist
(trusty was not-affected [code not present])
wily Not vulnerable
(code not present)
vivid Not vulnerable
(code not present)