JasPer 'jpc_dec.c' Denial of Service Vulnerability



JasPer is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to cause a denial-of-service condition.

JasPer 2.0.13 is vulnerable; prior versions may also be affected.

Information

Bugtraq ID: 100861
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2017-14229

Remote: Yes
Local: No
Published: Sep 11 2017 12:00AM
Updated: Jan 16 2019 07:00AM
Credit: team OWL337
Vulnerable: Redhat RHEV-M for Servers 0
Redhat Enterprise Linux 7
Redhat Enterprise Linux 6
+ Trustix Secure Enterprise Linux 2.0
+ Trustix Secure Linux 2.2
+ Trustix Secure Linux 2.1
+ Trustix Secure Linux 2.0
Redhat Enterprise Linux 5
Oracle Outside In Technology 8.5.3
JasPer JasPer 2.0.13


Not Vulnerable:

Exploit


The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.


Related Posts