CVE-2008-3520
jasper: multiple integer overflows in jas_alloc calls
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
Múltiples desbordamientos de entero en JasPer v1.900.1 pueden permitir a atacantes dependientes de contexto tener un impacto desconocido a través de ficheros de imagen manipuladas, relacionado con la multiplicación de enteros para localizaciones de memoria.
Red Hat Enterprise Virtualization Manager provides access to virtual machines using SPICE. These SPICE client packages provide the SPICE client and usbclerk service for both Windows 32-bit operating systems and Windows 64-bit operating systems. This update adds support for the TLS Fallback Signaling Cipher Suite Value, which can be used to prevent protocol downgrade attacks against applications which re-connect using a lower SSL/TLS protocol version when the initial connection indicating the highest supported protocol version fails.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-08-07 CVE Reserved
- 2008-10-02 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/33173 | Third Party Advisory | |
http://secunia.com/advisories/34391 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45621 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10141 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bugs.gentoo.org/show_bug.cgi?id=222819 | 2017-09-29 | |
http://www.securityfocus.com/bid/31470 | 2017-09-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jasper Project Search vendor "Jasper Project" | Jasper Search vendor "Jasper Project" for product "Jasper" | 1.900.1 Search vendor "Jasper Project" for product "Jasper" and version "1.900.1" | - |
Affected
|