CVE-2018-9252

Severity
6.5MEDIUM
EPSS
0.5%
top 34.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 4
Latest updateMay 13

Description

JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-5x2c-7cwv-6fv6: JasPer 22022-05-13
OSV
CVE-2018-9252: JasPer 22018-04-04
CVEList
CVE-2018-9252: JasPer 22018-04-04

📋Vendor Advisories

1
Red Hat
jasper: reachable assertion in jpc_abstorelstepsize() in jpc_enc.c2018-04-02

💬Community

4
Bugzilla
CVE-2018-9252 jasper: reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c [fedora-all]2018-04-09
Bugzilla
CVE-2018-9252 mingw-jasper: jasper: reachable assertion in jpc_abstorelstepsize() in jpc_enc.c [fedora-all]2018-04-09
Bugzilla
CVE-2018-9252 jasper: reachable assertion in jpc_abstorelstepsize() in jpc_enc.c2018-04-09
Bugzilla
CVE-2018-9252 mingw-jasper: jasper: reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c [epel-7]2018-04-09