CVE-2017-6852: Buffer Overflow
Published Mar 15, 2017
·Updated
Heap-based buffer overflow in the jpcdecdecodepkt function in jpct2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
Affected Software
1 affected component
Jasper Project Jasper<=2.0.9
Remediation
Patch Available
Event History
Mar 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6852?
CVE-2017-6852 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2017-6852?
To mitigate CVE-2017-6852, update JasPer to version 2.0.10 or later, as this version addresses the vulnerability.
3
What type of vulnerability is CVE-2017-6852?
CVE-2017-6852 is a heap-based buffer overflow vulnerability that affects the jpc_dec_decodepkt function.
4
Who is affected by CVE-2017-6852?
CVE-2017-6852 affects users of JasPer versions up to and including 2.0.9.
5
Can CVE-2017-6852 be exploited remotely?
Yes, CVE-2017-6852 can be exploited by remote attackers through crafted images.