First published: Sun Dec 30 2018(Updated: )
JasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Project Jasper | =2.0.14 | |
Debian Debian Linux | =8.0 | |
Oracle Outside In Technology | =8.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-20584.
The severity level of CVE-2018-20584 is medium.
CVE-2018-20584 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.
JasPer 2.0.14, Debian Linux 8.0, and Oracle Outside In Technology 8.5.4 are affected by CVE-2018-20584.
You can find more information about CVE-2018-20584 at the following references: [Security Focus](http://www.securityfocus.com/bid/106356), [GitHub](https://github.com/mdadams/jasper/issues/192), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html).