Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-9252

Опубликовано: 02 апр. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

A vulnerability was found in Jasper due to a flaw in the jpc_abstorelstepsize function within libjasper/jpc/jpc_enc.c, where an attacker can cause a denial of service, leading to the application crashing when triggered by specially crafted input.

Отчет

This vulnerability is rated as a moderate because it allows denial of service due to a reachable assertion in the jpc_abstorelstepsize function within libjasper/jpc/jpc_enc.c. Processing specially crafted input may trigger this issue, causing an application crash and affecting availability, it does not lead to code execution. The following products are now in Extended Life Phase of the support and maintenance life cycle.

  • Red Hat Enterprise Linux 5
  • Red Hat Enterprise Virtualization 3 The following products are now in Maintenance Phase 2 of the support and maintenance life cycle.
  • Red Hat Enterprise Linux 6 This issue is not currently planned to be addressed in future updates of these products. For additional information, please refer to the Life Cycle and Update Policies: https://access.redhat.com/support/policy/update_policies/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmWill not fix
Red Hat Enterprise Linux 6jasperWill not fix
Red Hat Enterprise Linux 7jasperWill not fix
Red Hat Enterprise Linux 8jasperWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=1565333jasper: reachable assertion in jpc_abstorelstepsize() in jpc_enc.c

EPSS

Процентиль: 80%
0.02066
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

CVSS3: 6.5
nvd
больше 8 лет назад

JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

CVSS3: 6.5
debian
больше 8 лет назад

JasPer 2.0.14 allows denial of service via a reachable assertion in th ...

CVSS3: 6.5
github
больше 4 лет назад

JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

suse-cvrf
почти 6 лет назад

Security update for jasper

EPSS

Процентиль: 80%
0.02066
Низкий

6.5 Medium

CVSS3