CVE-2017-13749: High severity jasper reports vulnerability
Published Aug 29, 2017
·Updated
There is a reachable assertion abort in the function jpcpinextrpcl() in jpc/jpct2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
Affected Software
3 affected components
Jasper Project Jasper=2.0.12
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13749?
CVE-2017-13749 has a severity rating that indicates it can lead to a remote denial of service.
2
How do I fix CVE-2017-13749?
To fix CVE-2017-13749, you should upgrade to a patch that addresses the issue in JasPer or affected Fedora versions.
3
Which versions of software are affected by CVE-2017-13749?
CVE-2017-13749 affects JasPer version 2.0.12 and Fedora versions 32 and 33.
4
Is there a workaround for CVE-2017-13749?
There is no official workaround for CVE-2017-13749, and upgrading is the recommended solution.
5
What is the nature of the vulnerability in CVE-2017-13749?
CVE-2017-13749 is a reachable assertion abort in the function jpc_pi_nextrpcl() that can cause exploitation.