7.5

CVE-2016-9398

The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jasper Project ≫ Jasper Version < 1.900.17
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Leap Version 42.2
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Desktop Version 12 Update sp2
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 12 Update sp2
Suse ≫ Linux Enterprise Server Version 12 Update sp2 HwPlatform raspberry_pi
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.98% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00082.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00085.html
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2016/11/17/1
Patch
Third Party Advisory
VDB Entry
Mailing List
https://blogs.gentoo.org/ago/2016/11/16/jasper-multiple-assertion-failure
Patch
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00008.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00009.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N4ALB4SXHURLVWKAOKYRNJXPABW3M22M/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UPOVZTSIQPW2H4AFLMI3LHJEZGBVEQET/
http://www.securityfocus.com/bid/94382
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1396980
Patch
Third Party Advisory
Issue Tracking