CVE-2017-13746: High severity jasper reports vulnerability
Published Aug 29, 2017
·Updated
There is a reachable assertion abort in the function jpcdecprocesssiz() in jpc/jpcdec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.
Affected Software
3 affected components
Jasper Project Jasper=2.0.12
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13746?
CVE-2017-13746 is classified as a denial of service vulnerability.
2
How does CVE-2017-13746 lead to a denial of service?
CVE-2017-13746 can cause a remote denial of service due to a reachable assertion abort in the function jpc_dec_process_siz() in JasPer 2.0.12.
3
Which versions of JasPer are affected by CVE-2017-13746?
CVE-2017-13746 affects JasPer version 2.0.12.
4
How can I mitigate CVE-2017-13746?
To mitigate CVE-2017-13746, it is recommended to upgrade to a patched version of JasPer or apply relevant security patches from your distribution.
5
What platforms are impacted by CVE-2017-13746?
CVE-2017-13746 impacts Fedora versions 32 and 33 in addition to JasPer 2.0.12.