CVE-2017-6851: Medium severity Jasper Project Jasper vulnerability
Published Mar 15, 2017
·Updated
The jasmatrixbindsub function in jasseq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
Affected Software
1 affected component
Jasper Project Jasper<=2.0.9
Remediation
Patch Available
Event History
Mar 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6851?
CVE-2017-6851 has been classified as a denial of service vulnerability due to an invalid read that can be triggered by crafted images.
2
Which software versions are affected by CVE-2017-6851?
CVE-2017-6851 affects JasPer versions up to and including 2.0.9.
3
How do I fix CVE-2017-6851?
To fix CVE-2017-6851, you should update to a patched version of JasPer that is higher than 2.0.9.
4
What type of attack does CVE-2017-6851 enable?
CVE-2017-6851 enables remote attackers to cause a denial of service condition.
5
Can CVE-2017-6851 be exploited without prior access?
Yes, CVE-2017-6851 can be exploited remotely by sending crafted images to the vulnerable application.