CVE-2017-13752: High severity jasper reports vulnerability
Published Aug 29, 2017
·Updated
There is a reachable assertion abort in the function jpcdequantize() in jpc/jpcdec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
Affected Software
3 affected components
Jasper Project Jasper=2.0.12
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13752?
CVE-2017-13752 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-13752?
To fix CVE-2017-13752, update to Jasper version 2.0.14 or later.
3
What types of attacks does CVE-2017-13752 enable?
CVE-2017-13752 enables remote denial of service attacks by causing an assertion abort.
4
Which versions of Jasper are affected by CVE-2017-13752?
CVE-2017-13752 affects Jasper version 2.0.12.
5
Is CVE-2017-13752 present in Fedora releases?
Yes, CVE-2017-13752 impacts Fedora versions 32 and 33 due to the inclusion of Jasper 2.0.12.