CVE-2018-9252
openSUSE Security Advisory - openSUSE-SU-2020:1523-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.
JasPer 2.0.14 permite una denegación de servicio (DoS) mediante una aserción alcanzable en la función jpc_abstorelstepsize en libjasper/jpc/jpc_enc.c.
An update that fixes 14 vulnerabilities is now available. This update for jasper fixes the following issues. Improved patch for already fixed issue. Fixed assert in calcstepsizes. Validate component depth bit. Check bounds in jas_seq2d_bindsub. Check bounds in jas_seq2d_bindsub. Check bounds in jas_seq2d_bindsub. Fixed heap base overflow in by checking components. Fixed reachable assertion in jpc_abstorelstepsize. Fixed null pointer deref in ras_putdatastd. Fixed mem leaks by registering jpc_unk_destroyparms. Fixed numchans mixup. Fixed heap based buffer over-read in jp2_encode. Fixed memory leak in jas_malloc.c. This update was imported from the SUSE:SLE-15:Update update project.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-03 CVE Reserved
- 2018-04-04 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-06-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-617: Reachable Assertion
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.oracle.com/security-alerts/cpuapr2020.html | X_refsource_misc |
|
URL | Date | SRC |
---|---|---|
https://github.com/mdadams/jasper/issues/173 | 2024-08-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jasper Project Search vendor "Jasper Project" | Jasper Search vendor "Jasper Project" for product "Jasper" | 2.0.14 Search vendor "Jasper Project" for product "Jasper" and version "2.0.14" | - |
Affected
|