CVE-2017-13751: High severity jasper reports vulnerability
Published Aug 29, 2017
·Updated
There is a reachable assertion abort in the function calcstepsizes() in jpc/jpcdec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
Affected Software
3 affected components
Jasper Project Jasper=2.0.12
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13751?
CVE-2017-13751 has a severity rating of medium and can lead to a remote denial of service attack.
2
How do I fix CVE-2017-13751?
To fix CVE-2017-13751, it is recommended to update to a patched version of JasPer beyond 2.0.12.
3
Which versions of software are affected by CVE-2017-13751?
CVE-2017-13751 affects JasPer version 2.0.12 and Fedora versions 32 and 33.
4
What is the nature of the vulnerability in CVE-2017-13751?
CVE-2017-13751 involves a reachable assertion abort in the calcstepsizes() function.
5
Can CVE-2017-13751 be exploited remotely?
Yes, CVE-2017-13751 can be exploited remotely, potentially leading to application crashes.