CVE-2017-1000050

Severity
7.5HIGH
EPSS
1.6%
top 18.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateMay 13

Description

JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Also affects: Fedora 32, 33, Ubuntu Linux 14.04, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-29wp-q2r7-4jqv: JasPer 22022-05-13
OSV
CVE-2017-1000050: JasPer 22017-07-17
CVEList
CVE-2017-1000050: JasPer 22017-07-13

📋Vendor Advisories

2
Ubuntu
JasPer vulnerabilities2018-06-27
Red Hat
jasper: NULL pointer exception in jp2_encode()2017-03-05

💬Community

4
Bugzilla
CVE-2017-1000050 jasper: NULL pointer exception in jp2_encode()2017-07-19
Bugzilla
CVE-2016-10248 CVE-2016-10251 CVE-2017-1000050 CVE-2017-13745 CVE-2017-13746 CVE-2017-13747 CVE-2017-13748 CVE-2017-13749 CVE-2017-13750 CVE-2017-13751 CVE-2017-13752 CVE-2017-14132 CVE-2017-6850 CVE-2017-03-21
Bugzilla
CVE-2016-10251 CVE-2017-1000050 CVE-2017-13745 CVE-2017-13746 CVE-2017-13747 CVE-2017-13748 CVE-2017-13749 CVE-2017-13750 CVE-2017-13751 CVE-2017-13752 CVE-2017-14132 CVE-2017-6850 CVE-2017-6851 CVE-22017-03-21
Bugzilla
CVE-2016-9396 CVE-2016-9397 CVE-2016-9398 CVE-2016-9399 CVE-2017-1000050 CVE-2017-13745 CVE-2017-13746 CVE-2017-13747 CVE-2017-13748 CVE-2017-13749 CVE-2017-13750 CVE-2017-13751 CVE-2017-13752 CVE-2012017-03-21
CVE-2017-1000050 (HIGH CVSS 7.5) | JasPer 2.0.12 is vulnerable to a NU | cvebase.io