Reachable assertion in JasPer - CVE-2024-31744

 

Reachable assertion in JasPer - CVE-2024-31744

Published: October 15, 2024


Vulnerability identifier: #VU98599
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31744
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion within the jpc_streamlist_remove() function in src/libjasper/jpc/jpc_dec.c. A remote attacker can pass a specially crafted image to the application and perform a denial of service (DoS) attack.


Affected software

JasPer
Anolis OS
Oracle Solaris
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Exposure Function
jasper
jasper-devel
jasper-libs
jasper-utils
jasper-doc

How to mitigate CVE-2024-31744

Install updates from vendor's website.

JasPer - update to 4.2.3
jasper - update to 4.0.0-3
jasper-devel - update to 4.0.0-3
jasper-libs - update to 4.0.0-3
jasper-utils - update to 4.0.0-3
jasper-doc - update to 4.0.0-3
Oracle Solaris - update to 11.4 SRU 74

External References

Related Security Bulletins