CVE-2017-7976 PUBLISHED

Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file, leading to a denial of service (application crash) or disclosure of sensitive information from process memory.

EPSS 0.29% · 52.4th percentile

Risk Scores

EPSS Score
0.29%
52.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSjbig2dec0, 0.12-2, 0.12+20150918-1
Ubuntu:14.04:LTSjbig2dec0, 0.11+20120125-1ubuntu1

Timeline

References

Open in Interactive Console →