CVE-2017-13747: High severity jasper reports vulnerability
Published Aug 29, 2017
·Updated
There is a reachable assertion abort in the function jpcfloorlog2() in jpc/jpcmath.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
Affected Software
3 affected components
Jasper Project Jasper=2.0.12
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13747?
CVE-2017-13747 has a severity rating of medium due to its potential for remote denial of service attacks.
2
How do I fix CVE-2017-13747?
To fix CVE-2017-13747, upgrade to a patched version of JasPer or apply the fix provided in the corresponding security updates.
3
What versions are affected by CVE-2017-13747?
CVE-2017-13747 affects JasPer version 2.0.12 and specific versions of Fedora 32 and 33.
4
What systems are impacted by CVE-2017-13747?
CVE-2017-13747 impacts systems running JasPer 2.0.12 and Fedora versions 32 and 33.
5
Is CVE-2017-13747 easily exploitable?
Yes, CVE-2017-13747 is considered easily exploitable, allowing a remote attacker to trigger the vulnerability.