CVE-2018-19542
https://notcve.org/view.php?id=CVE-2018-19542
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service. Se ha descubierto un problema en JasPer 2.0.14. Hay una desreferencia de puntero NULL en la función jp2_decode en libjasper/jp2/jp2_dec.c, provocando una denegación de servicio (DoS). • http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00004.html https://github.com/mdadams/jasper/issues/182 https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html https://www.oracle.com/security-alerts/cpuapr2020.html • CWE-476: NULL Pointer Dereference •
CVE-2018-19539
https://notcve.org/view.php?id=CVE-2018-19539
An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service. Se ha descubierto un problema en JasPer 2.0.14. Hay una violación de acceso en la función jas_image_readcmpt en libjasper/base/jas_image.c, provocando una denegación de servicio (DoS). • http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00004.html https://github.com/mdadams/jasper/issues/182 https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html https://www.oracle.com/security-alerts/cpuapr2020.html • CWE-617: Reachable Assertion •
CVE-2018-19492
https://notcve.org/view.php?id=CVE-2018-19492
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend. Se ha descubierto un problema en cairo.trm en Gnuplot 5.2.5. • http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00066.html https://lists.debian.org/debian-lts-announce/2018/11/msg00031.html https://lists.debian.org/debian-lts-announce/2018/11/msg00035.html https://sourceforge.net/p/gnuplot/bugs/2089 https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949 https://usn.ubuntu.com/4541-1 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2018-19490
https://notcve.org/view.php?id=CVE-2018-19490
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function. Se ha descubierto un problema en Gnuplot 5.2.5. Este problema permite a un atacante realizar un desbordamiento de búfer basado en memoria dinámica (heap) con una cantidad arbitraria de datos en df_generate_ascii_array_entry. • http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00066.html https://lists.debian.org/debian-lts-announce/2018/11/msg00031.html https://lists.debian.org/debian-lts-announce/2018/11/msg00035.html https://sourceforge.net/p/gnuplot/bugs/2093 https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949 https://usn.ubuntu.com/4541-1 • CWE-787: Out-of-bounds Write •
CVE-2018-19491
https://notcve.org/view.php?id=CVE-2018-19491
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend. Se ha descubierto un problema en post.trm en Gnuplot 5.2.5. • http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00066.html https://lists.debian.org/debian-lts-announce/2018/11/msg00031.html https://lists.debian.org/debian-lts-announce/2018/11/msg00035.html https://sourceforge.net/p/gnuplot/bugs/2094 https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949 https://usn.ubuntu.com/4541-1 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •