Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40755

Опубликовано: 17 сент. 2022
Источник: redhat
CVSS3: 5.5

Описание

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

A vulnerability was found in JasPer. A reachable assertion in the inttobits function in libjasper/base/jas_image.c, leads to a denial of service.

Отчет

Red Hat has determined this flaw to be of low impact as successful exploitation results in a crash (denial of service) of the application and does not impact system-wide stability or lead to arbitrary code execution or memory corruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jasperOut of support scope
Red Hat Enterprise Linux 7jasperOut of support scope
Red Hat Enterprise Linux 8jasperFix deferred
Red Hat Enterprise Linux 9jasperFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2133696jasper: Reachable assertion in inttobits, jas_image.c

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

CVSS3: 5.5
nvd
больше 3 лет назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

CVSS3: 5.5
debian
больше 3 лет назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the ...

CVSS3: 5.5
github
больше 3 лет назад

JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.

5.5 Medium

CVSS3