CVE-2008-3522
jasper: possible buffer overflow in jas_stream_printf()
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.
Desbordamiento de búfer en la función jas_stream_printf de libjasper/base/jas_stream.c en JasPer v1.900.1 puede permitir a atacantes dependientes de contexto tener un impacto desconocido a través de vectores relacionados con la función mif_hdr_put y la utilización de vsprintf.
Red Hat Enterprise Virtualization Manager provides access to virtual machines using SPICE. These SPICE client packages provide the SPICE client and usbclerk service for both Windows 32-bit operating systems and Windows 64-bit operating systems. This update adds support for the TLS Fallback Signaling Cipher Suite Value, which can be used to prevent protocol downgrade attacks against applications which re-connect using a lower SSL/TLS protocol version when the initial connection indicating the highest supported protocol version fails.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-08-07 CVE Reserved
- 2008-10-02 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-122: Heap-based Buffer Overflow
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://bugs.gentoo.org/show_bug.cgi?id=222819 | X_refsource_misc | |
http://secunia.com/advisories/33173 | Third Party Advisory | |
http://secunia.com/advisories/34391 | Third Party Advisory | |
http://www.securityfocus.com/bid/31470 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45623 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://bugs.gentoo.org/attachment.cgi?id=163282&action=view | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Enterprise Virtualization Search vendor "Redhat" for product "Enterprise Virtualization" | 3.5 Search vendor "Redhat" for product "Enterprise Virtualization" and version "3.5" | - |
Affected
| ||||||
Jasper Project Search vendor "Jasper Project" | Jasper Search vendor "Jasper Project" for product "Jasper" | 1.900.1 Search vendor "Jasper Project" for product "Jasper" and version "1.900.1" | - |
Affected
|