Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40755

Опубликовано: 17 сент. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

A vulnerability was found in JasPer. A reachable assertion in the inttobits function in libjasper/base/jas_image.c, leads to a denial of service.

Отчет

Red Hat has determined this flaw to be of low impact as successful exploitation results in a crash (denial of service) of the application and does not impact system-wide stability or lead to arbitrary code execution or memory corruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jasperOut of support scope
Red Hat Enterprise Linux 7jasperOut of support scope
Red Hat Enterprise Linux 8jasperFix deferred
Red Hat Enterprise Linux 9jasperFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2133696jasper: Reachable assertion in inttobits, jas_image.c

EPSS

Процентиль: 29%
0.00363
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

CVSS3: 5.5
nvd
почти 4 года назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

CVSS3: 5.5
debian
почти 4 года назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the ...

CVSS3: 5.5
github
почти 4 года назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

EPSS

Процентиль: 29%
0.00363
Низкий

5.5 Medium

CVSS3