Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-3521
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-3521

Description:
Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file, which causes Jasper to exit. NOTE: this was originally reported as a symlink issue, but this was incorrect. NOTE: some vendors dispute the severity of this issue, but it satisfies CVE's requirements for inclusion.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/45622

UBUNTU
  http://www.ubuntu.com/usn/USN-742-1

SAID
  Secunia Advisory: SA34391

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2009:164
  http://www.mandriva.com/security/advisories?name=MDVSA-2009:142

CONFIRM
  http://bugs.gentoo.org/show_bug.cgi?id=222819
  http://bugs.gentoo.org/attachment.cgi?id=163282&action=view

BID
  31470


Return to the previous page.