Reachable assertion in JasPer - CVE-2024-31744
Published: October 15, 2024
Vulnerability identifier: #VU98599
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31744
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion within the jpc_streamlist_remove() function in src/libjasper/jpc/jpc_dec.c. A remote attacker can pass a specially crafted image to the application and perform a denial of service (DoS) attack.
Affected software
JasPer
Anolis OS
Oracle Solaris
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Exposure Function
jasper
jasper-devel
jasper-libs
jasper-utils
jasper-doc
Anolis OS
Oracle Solaris
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Exposure Function
jasper
jasper-devel
jasper-libs
jasper-utils
jasper-doc
How to mitigate CVE-2024-31744
Install updates from vendor's website.
JasPer - update to 4.2.3
jasper - update to 4.0.0-3
jasper-devel - update to 4.0.0-3
jasper-libs - update to 4.0.0-3
jasper-utils - update to 4.0.0-3
jasper-doc - update to 4.0.0-3
Oracle Solaris - update to 11.4 SRU 74
jasper - update to 4.0.0-3
jasper-devel - update to 4.0.0-3
jasper-libs - update to 4.0.0-3
jasper-utils - update to 4.0.0-3
jasper-doc - update to 4.0.0-3
Oracle Solaris - update to 11.4 SRU 74
External References
Related Security Bulletins
- Denial of service in Jasper
- Oracle Solaris update for third-party components
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Anolis OS update for jasper
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function