CVE-2017-5498: Medium severity Jasper Project Jasper vulnerability
Published Mar 1, 2017
·Updated
libjasper/include/jasper/jasmath.h in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
Affected Software
1 affected component
Jasper Project Jasper=1.900.17
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5498?
CVE-2017-5498 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-5498?
You can fix CVE-2017-5498 by upgrading to a version of JasPer that is not vulnerable, preferably later than 1.900.17.
3
What does CVE-2017-5498 affect?
CVE-2017-5498 affects JasPer version 1.900.17.
4
Can CVE-2017-5498 be exploited remotely?
Yes, CVE-2017-5498 can be exploited by remote attackers to cause a denial of service.
5
What happens if CVE-2017-5498 is exploited?
Exploitation of CVE-2017-5498 can lead to a crash of the application using the affected version of JasPer.