Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19542

Опубликовано: 13 июл. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

A vulnerability was found in Jasper due to a NULL pointer dereference in the jp2_decode function within libjasper/jp2/jp2_dec.c, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash and resulting in a denial of service condition.

Отчет

This vulnerability was rated as LOW severity because it requires the victim to open a specially crafted file, it doesn't allow full system compromise, it can cause the application to crash temporarily.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperWill not fix
Red Hat Enterprise Linux 7jasperFix deferred
Red Hat Enterprise Linux 8jasperFix deferred
Red Hat Enterprise Linux 8mingw-jasperFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1658791jasper: invalid access in jp2_decode in libjasper/jp2/jp2_dec.c

EPSS

Процентиль: 78%
0.01946
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

CVSS3: 6.5
nvd
больше 7 лет назад

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

CVSS3: 6.5
debian
больше 7 лет назад

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dere ...

CVSS3: 6.5
github
больше 4 лет назад

An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

CVSS3: 6.5
fstec
около 8 лет назад

Уязвимость функции jp2_decode (libjasper/jp2/jp2_dec.c) набора библиотек JasPer, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 78%
0.01946
Низкий

3.3 Low

CVSS3