int(3238)

Boletines de Vulnerabilidades


Denegación de servicio en JasPer JPEG-2000

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Denegación de Servicio
Dificultad Experto
Requerimientos del atacante Acceso remoto sin cuenta a un servicio estandar

Información sobre el sistema

Propiedad Valor
Fabricante afectado GNU/Linux
Software afectado JasPer JPEG-2000 library < 1.900

Descripción

Se ha encontrado una vulnerabilidad en la librería JasPer JPEG-2000 en versiones anteriores a la 1.900. La vulnerabilidad reside en un error en el archivo jpc/jpc_cs.c en la función jpc_qcx_getcompparms.

Un atacante remoto podría causar una denegación de servicio y posiblemente corromper el heap mediante archivos de imágenes especialmente diseñados.

Solución



Actualización de software

Mandriva

Mandriva Linux 2007
X86
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/jasper-1.701.0-5.2mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/libjasper1.701_1-1.701.0-5.2mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/libjasper1.701_1-devel-1.701.0-5.2mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/i586/libjasper1.701_1-static-devel-1.701.0-5.2mdv2007.0.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/SRPMS/jasper-1.701.0-5.2mdv2007.0.src.rpm
X86_64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/jasper-1.701.0-5.2mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/lib64jasper1.701_1-1.701.0-5.2mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/lib64jasper1.701_1-devel-1.701.0-5.2mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/x86_64/lib64jasper1.701_1-static-devel-1.701.0-5.2mdv2007.0.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.0/SRPMS/jasper-1.701.0-5.2mdv2007.0.src.rpm

Corporate Server 4.0
X86
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/i586/jasper-1.701.0-3.2.20060mlcs4.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/i586/libjasper1.701_1-1.701.0-3.2.20060mlcs4.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/i586/libjasper1.701_1-devel-1.701.0-3.2.20060mlcs4.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/i586/libjasper1.701_1-static-devel-1.701.0-3.2.20060mlcs4.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/SRPMS/jasper-1.701.0-3.2.20060mlcs4.src.rpm
X86_64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/x86_64/jasper-1.701.0-3.2.20060mlcs4.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/x86_64/lib64jasper1.701_1-1.701.0-3.2.20060mlcs4.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/x86_64/lib64jasper1.701_1-devel-1.701.0-3.2.20060mlcs4.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/x86_64/lib64jasper1.701_1-static-devel-1.701.0-3.2.20060mlcs4.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/corporate/4.0/SRPMS/jasper-1.701.0-3.2.20060mlcs4.src.rpm

Mandriva Linux 2007.1
X86
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/jasper-1.701.0-6.2mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/libjasper1.701_1-1.701.0-6.2mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/libjasper1.701_1-devel-1.701.0-6.2mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/i586/libjasper1.701_1-static-devel-1.701.0-6.2mdv2007.1.i586.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/SRPMS/jasper-1.701.0-6.2mdv2007.1.src.rpm
X86_64
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/jasper-1.701.0-6.2mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/lib64jasper1.701_1-1.701.0-6.2mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/lib64jasper1.701_1-devel-1.701.0-6.2mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/x86_64/lib64jasper1.701_1-static-devel-1.701.0-6.2mdv2007.1.x86_64.rpm
ftp://ftp.ps.pl/mirrors/Mandrakelinux/official/updates/2007.1/SRPMS/jasper-1.701.0-6.2mdv2007.1.src.rpm

Mandriva (MDKSA-2007:208)

Mandriva Linux 2008.0
X86
2008.0/i586/ghostscript-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/ghostscript-X-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/ghostscript-common-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/ghostscript-doc-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/ghostscript-dvipdf-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/ghostscript-module-X-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/libgs8-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/libgs8-devel-8.60-55.1mdv2008.0.i586.rpm
2008.0/i586/libijs1-0.35-55.1mdv2008.0.i586.rpm
2008.0/i586/libijs1-devel-0.35-55.1mdv2008.0.i586.rpm
2008.0/SRPMS/ghostscript-8.60-55.1mdv2008.0.src.rpm
X86_64
2008.0/x86_64/ghostscript-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/ghostscript-X-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/ghostscript-common-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/ghostscript-doc-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/ghostscript-dvipdf-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/ghostscript-module-X-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/lib64gs8-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/lib64gs8-devel-8.60-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/lib64ijs1-0.35-55.1mdv2008.0.x86_64.rpm
2008.0/x86_64/lib64ijs1-devel-0.35-55.1mdv2008.0.x86_64.rpm
2008.0/SRPMS/ghostscript-8.60-55.1mdv2008.0.src.rpm

Mandriva (MDKSA-2007:209)

Mandriva Linux 2007
X86
2007.0/i586/libnetpbm10-10.34-2.1mdv2007.0.i586.rpm
2007.0/i586/libnetpbm10-devel-10.34-2.1mdv2007.0.i586.rpm
2007.0/i586/libnetpbm10-static-devel-10.34-2.1mdv2007.0.i586.rpm
2007.0/i586/netpbm-10.34-2.1mdv2007.0.i586.rpm
2007.0/SRPMS/netpbm-10.34-2.1mdv2007.0.src.rpm
X86_64
2007.0/x86_64/lib64netpbm10-10.34-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/lib64netpbm10-devel-10.34-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/lib64netpbm10-static-devel-10.34-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/netpbm-10.34-2.1mdv2007.0.x86_64.rpm
2007.0/SRPMS/netpbm-10.34-2.1mdv2007.0.src.rpm

Corporate Server 4.0
X86
corporate/4.0/i586/libnetpbm10-10.29-1.4.20060mlcs4.i586.rpm
corporate/4.0/i586/libnetpbm10-devel-10.29-1.4.20060mlcs4.i586.rpm
corporate/4.0/i586/libnetpbm10-static-devel-10.29-1.4.20060mlcs4.i586.rpm
corporate/4.0/i586/netpbm-10.29-1.4.20060mlcs4.i586.rpm
corporate/4.0/SRPMS/netpbm-10.29-1.4.20060mlcs4.src.rpm
X86_64
corporate/4.0/x86_64/lib64netpbm10-10.29-1.4.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/lib64netpbm10-devel-10.29-1.4.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/lib64netpbm10-static-devel-10.29-1.4.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/netpbm-10.29-1.4.20060mlcs4.x86_64.rpm
corporate/4.0/SRPMS/netpbm-10.29-1.4.20060mlcs4.src.rpm

Mandriva Linux 2007.1
X86
2007.1/i586/libnetpbm10-10.34-4.1mdv2007.1.i586.rpm
2007.1/i586/libnetpbm10-devel-10.34-4.1mdv2007.1.i586.rpm
2007.1/i586/libnetpbm10-static-devel-10.34-4.1mdv2007.1.i586.rpm
2007.1/i586/netpbm-10.34-4.1mdv2007.1.i586.rpm
2007.1/SRPMS/netpbm-10.34-4.1mdv2007.1.src.rpm
X86_64
2007.1/x86_64/lib64netpbm10-10.34-4.1mdv2007.1.x86_64.rpm
2007.1/x86_64/lib64netpbm10-devel-10.34-4.1mdv2007.1.x86_64.rpm
2007.1/x86_64/lib64netpbm10-static-devel-10.34-4.1mdv2007.1.x86_64.rpm
2007.1/x86_64/netpbm-10.34-4.1mdv2007.1.x86_64.rpm
2007.1/SRPMS/netpbm-10.34-4.1mdv2007.1.src.rpm

Mandriva Linux 2008.0
X86
2008.0/i586/libnetpbm-devel-10.34-8.1mdv2008.0.i586.rpm
2008.0/i586/libnetpbm-static-devel-10.34-8.1mdv2008.0.i586.rpm
2008.0/i586/libnetpbm10-10.34-8.1mdv2008.0.i586.rpm
2008.0/i586/netpbm-10.34-8.1mdv2008.0.i586.rpm
2008.0/SRPMS/netpbm-10.34-8.1mdv2008.0.src.rpm
X86_64
2008.0/x86_64/lib64netpbm-devel-10.34-8.1mdv2008.0.x86_64.rpm
2008.0/x86_64/lib64netpbm-static-devel-10.34-8.1mdv2008.0.x86_64.rpm
2008.0/x86_64/lib64netpbm10-10.34-8.1mdv2008.0.x86_64.rpm
2008.0/x86_64/netpbm-10.34-8.1mdv2008.0.x86_64.rpm
2008.0/SRPMS/netpbm-10.34-8.1mdv2008.0.src.rpm

Identificadores estándar

Propiedad Valor
CVE CVE-2007-2721
BID 24052

Recursos adicionales

Mandriva Security Advisory (MDKSA-2007:129)
http://www.mandriva.com/security/advisories?name=MDKSA-2007:129

Mandriva Security Advisory (MDKSA-2007:208)
http://www.mandriva.com/security/advisories?name=MDKSA-2007:208

Mandriva Security Advisory (MDKSA-2007:209)
http://www.mandriva.com/security/advisories?name=MDKSA-2007:209

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2007-06-20
1.1 Aviso emitido por Mandriva (MDKSA-2007:208), aviso emitido por Mandriva (MDKSA-2007:209) 2007-11-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT