Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5500

Опубликовано: 01 мар. 2017
Источник: debian
EPSS Низкий

Описание

libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jasperremovedpackage

Примечания

  • Triggers an assert. Not suitable for code injection, hardly denial of service

  • Reproducer: https://github.com/asarubbo/poc/blob/master/00019-jasper-leftshift-jpc_dec_c

  • http://blogs.gentoo.org/ago/2017/01/16/jasper-multiple-crashes-with-ubsan/

  • https://github.com/mdadams/jasper/issues/64

EPSS

Процентиль: 31%
0.00121
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

CVSS3: 2.5
redhat
больше 9 лет назад

libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

CVSS3: 5.5
nvd
почти 9 лет назад

libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

CVSS3: 5.5
github
больше 3 лет назад

libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

EPSS

Процентиль: 31%
0.00121
Низкий