JasPer 'jp2_dec.c' Remote Heap Buffer Overflow Vulnerability



JasPer is prone to a remote heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.

Attackers may leverage this issue to execute arbitrary code in the context of the application that uses the affected library. Failed attacks will cause denial-of-service conditions.

JasPer 2.0.12 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 99171
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Jun 20 2017 12:00AM
Updated: Jun 20 2017 12:00AM
Credit: Qixue Xiao and Kang Li.
Vulnerable: JasPer JasPer 2.0.12


Not Vulnerable:

Exploit


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.


Related Posts