JasPer is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition.
JasPer 2.0.13 is vulnerable; prior versions may also be affected.
Information
Redhat Enterprise Linux 7
Redhat Enterprise Linux 6
Redhat Enterprise Linux 5
Oracle Outside In Technology 8.5.3
JasPer JasPer 2.0.13
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References:
- CVE-2017-14229 (Redhat)
- Infinite loop in jpc_dec.c of Jasper. #146 (JasPer)
- JasPer Homepage (Micheal Adams)
- Bug 1058000 - (CVE-2017-14229) VUL-0: CVE-2017-14229: jasper: Infinite loop in (Novell)
- Bug 1491853 - (CVE-2017-14229) CVE-2017-14229 jasper: Infinite loop in jpc_dec_ (Redhat)
- Oracle Critical Patch Update Advisory - January 2019 (Oracle)