6.5

CVE-2018-20584

Exploit
JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jasper Project ≫ Jasper Version 2.0.14
Debian ≫ Debian Linux Version 8.0
Oracle ≫ Outside In Technology Version 8.5.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.89% 0.851
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch
Third Party Advisory
https://security.gentoo.org/glsa/201908-03
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/106356
Third Party Advisory
Broken Link
VDB Entry
https://github.com/mdadams/jasper/issues/192
Third Party Advisory
Exploit