« List of all CVEs

CVE-2014-8137

Published: 12/24/2014 Last updated: 8/6/2024 Reserved: 10/10/2014

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

grib

Products affected (1)

Product Vendor Version
n/a n/a < 1.23.1

References (42)