Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5499

Опубликовано: 01 мар. 2017
Источник: debian

Описание

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jasperremovedpackage

Примечания

  • Reproducer: https://github.com/asarubbo/poc/blob/master/00018-jasper-signedintoverflow-jpc_dec_c

  • http://blogs.gentoo.org/ago/2017/01/16/jasper-multiple-crashes-with-ubsan/

  • https://github.com/mdadams/jasper/issues/63

  • Triggers an assert. Not suitable for code injection, hardly denial of service

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 3.1
redhat
больше 9 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
nvd
почти 9 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

suse-cvrf
больше 5 лет назад

Security update for jasper