Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5501

Опубликовано: 01 мар. 2017
Источник: debian
EPSS Низкий

Описание

Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jasperremovedpackage

Примечания

  • Reproducer: https://github.com/asarubbo/poc/blob/master/00022-jasper-signedintoverflow-jpc_tsfb_c

  • http://blogs.gentoo.org/ago/2017/01/16/jasper-multiple-crashes-with-ubsan/

  • https://github.com/mdadams/jasper/issues/70

  • Only crashes with debug builds using ubsan

EPSS

Процентиль: 31%
0.00121
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 2.5
redhat
больше 9 лет назад

Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
nvd
почти 9 лет назад

Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

EPSS

Процентиль: 31%
0.00121
Низкий