Vulnerabilities > CVE-2017-14229 - Infinite Loop vulnerability in Jasper Project Jasper 2.0.13

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
jasper-project
CWE-835
nessus

Summary

There is an infinite loop in the jpc_dec_tileinit function in jpc/jpc_dec.c of Jasper 2.0.13. It will lead to a remote denial of service attack.

Vulnerable Configurations

Part Description Count
Application
Jasper_Project
1

Nessus

NASL familyGentoo Local Security Checks
NASL idGENTOO_GLSA-201908-03.NASL
descriptionThe remote host is affected by the vulnerability described in GLSA-201908-03 (JasPer: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in JasPer. Please review the CVE identifiers referenced below for details. Impact : Please review the referenced CVE identifiers for details. Workaround : There is no known workaround at this time.
last seen2020-06-01
modified2020-06-02
plugin id127561
published2019-08-12
reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/127561
titleGLSA-201908-03 : JasPer: Multiple vulnerabilities