CVE-2017-1000050: Null Pointer Dereference
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
Other sources
JasPer is vulnerable to a NULL pointer exception in the function jp2encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
References:
http://www.openwall.com/lists/oss-security/2017/03/06/1
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jasperto a version that resolves this vulnerability.Fixed in 2.0.13
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000050?
CVE-2017-1000050 is considered a medium severity vulnerability due to its potential to cause a denial-of-service.
How do I fix CVE-2017-1000050?
To fix CVE-2017-1000050, upgrade to JasPer version 2.0.13 or later.
What software is affected by CVE-2017-1000050?
CVE-2017-1000050 affects JasPer version 2.0.12 and earlier.
Can CVE-2017-1000050 be exploited remotely?
There is no direct indication that CVE-2017-1000050 can be exploited remotely as it typically requires local access to trigger the vulnerability.
What kind of attack does CVE-2017-1000050 enable?
CVE-2017-1000050 enables denial-of-service attacks due to a NULL pointer exception.