CVE-2024-31744Reachable Assertion in Azl3 Jasper 4.2.1-2 ON Azure Linux 3.0

Severity
7.5HIGHNVD
EPSS
0.0%
top 92.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 19
Latest updateJul 15

Description

In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
OSV
CVE-2024-31744: In Jasper 42024-04-19
GHSA
GHSA-4pvq-mcwh-v9jc: In Jasper 42024-04-19

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Risk Matrix: Platform (JasPer) — CVE-2024-317442025-07-15
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (JasPer) — CVE-2024-317442024-10-15
Microsoft
In Jasper 4.2.2 the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability allowing attackers to cause a denial of service attack through a specific 2024-04-09