Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5499

Опубликовано: 28 окт. 2016
Источник: redhat
CVSS3: 3.1

Описание

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

Отчет

This vulnerability is rated as low severity because it results in a denial of service, a remote attacker can crash the application using a crafted file, it does not affect system security or integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperNot affected
Red Hat Enterprise Linux 7jasperNot affected
Red Hat Enterprise Linux 8jasperWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1416061jasper: Signed integer overflow in jpc_dequantize() in jpc_dec.c

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
nvd
почти 9 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
debian
почти 9 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows ...

CVSS3: 5.5
github
больше 3 лет назад

Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.

suse-cvrf
больше 5 лет назад

Security update for jasper

3.1 Low

CVSS3