Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-4517

26
FAUCET Score

CVE-2011-4517 describes a heap-based buffer overflow vulnerability in the JasPer library (versions 1.900.1 and earlier), specifically within the jpc_crg_getparms function, affecting various Linux distributions and Oracle. This flaw allows remote attackers to execute arbitrary code or cause a denial of service by crafting a malicious JPEG2000 file. With a CVSS score of 6.8, it is considered of medium severity, requiring medium attack complexity but no authentication, and potentially leading to partial confidentiality, integrity, and availability impacts. Despite its age and potential impact, there is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.900.1CPE matchmatch criteria
cpe:2.3:a:jasper_project:jasper:1.900.1:*:*:*:*:*:*:*
8.3.5CPE matchmatch criteria
cpe:2.3:a:oracle:outside_in_technology:8.3.5:*:*:*:*:*:*:*
8.3.7CPE matchmatch criteria
cpe:2.3:a:oracle:outside_in_technology:8.3.7:*:*:*:*:*:*:*
10.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
10.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.62%
Probability of exploitation in next 30 days
EPSS Percentile
95.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1062 is in the 95th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: netpbm-0:10.35.58-8.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: netpbm-0:10.35.58-8.el5_7.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: jasper-0:1.900.1-15.el6_1.1
View patch
redhatpatch availablevia redhat_api
Product: RHEV Manager version 3.5Fixed in: spice-client-msi-0:3.5-3
View patch

Vendor Advisories (1)

redhatCVE-2011-4517Important

jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409)

Dec 8, 2011

References

lists.fedoraproject.org / pipermail/package-announce/2011-December/071458.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2012-January/071561.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2011-12/msg00010.html
Mailing ListThird Party Advisory
osvdb.org / 77596
Broken Link
rhn.redhat.com / errata/RHSA-2015-0698.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
secunia.com / advisories/47193
Not Applicable
secunia.com / advisories/47306
Not Applicable
secunia.com / advisories/47353
Not Applicable
exchange.xforce.ibmcloud.com / vulnerabilities/71701
Third Party AdvisoryVDB Entry
www-01.ibm.com / support/docview.wss
Broken Link
debian.org / security/2011/dsa-2371
Third Party Advisory
kb.cert.org / vuls/id/887409
Third Party AdvisoryUS Government Resource
oracle.com / technetwork/topics/security/cpujan2012-366304.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-1807.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-1811.html
Third Party Advisory
securityfocus.com / bid/50992
Broken LinkVDB Entry
slackware.com / security/viewer.php
Release Notes
ubuntu.com / usn/USN-1315-1
Third Party Advisory