CVE-2017-13745: High severity jasper reports vulnerability
Published Aug 29, 2017
·Updated
There is a reachable assertion abort in the function jpcdecprocesssot() in jpc/jpcdec.c in JasPer 2.0.12 that will lead to a remote denial of service attack by triggering an unexpected jpcppmstabtostreams return value, a different vulnerability than CVE-2018-9154.
Affected Software
1 affected component
Jasper Project Jasper=2.0.12
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13745?
CVE-2017-13745 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-13745?
To fix CVE-2017-13745, upgrade to a patched version of JasPer that addresses this vulnerability.
3
What causes CVE-2017-13745?
CVE-2017-13745 is caused by a reachable assertion abort in the jpc_dec_process_sot() function in JasPer 2.0.12.
4
Who is affected by CVE-2017-13745?
CVE-2017-13745 primarily affects users running JasPer version 2.0.12.
5
Can CVE-2017-13745 be exploited remotely?
Yes, CVE-2017-13745 can be exploited remotely, leading to a denial of service attack.