Bug 1488965 (CVE-2017-13752)
Summary: | CVE-2017-13752 jasper: reachable assertion in jpc_dequantize() | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | bmcclain, cfergeau, eedri, erik-fedora, jridky, lsurette, mgoldboi, michal.skrivanek, mike, rdieter, rh-spice-bugs, rjones, srevivo, ykaul |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-21 11:56:25 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1434464, 1434465, 1434467, 1485276, 1910587 | ||
Bug Blocks: | 1449402 |
Description
Andrej Nemec
2017-09-06 14:01:28 UTC
Created jasper tracking bugs for this issue: Affects: fedora-all [bug 1434464] Created mingw-jasper tracking bugs for this issue: Affects: epel-7 [bug 1434465] Affects: fedora-all [bug 1434467] hi, mostly of the recent open bugs about jasper are duplicate of this: https://blogs.gentoo.org/ago/2016/11/16/jasper-multiple-assertion-failure/ (In reply to Agostino Sarubbo from comment #2) > hi, mostly of the recent open bugs about jasper are duplicate of this: > https://blogs.gentoo.org/ago/2016/11/16/jasper-multiple-assertion-failure/ Hello Agostino, Thanks, I caught that from your post to oss-security as well. I'll duplicate them as soon as Mitre lets us know, as that's the most reliable process for us. This CVE is for the same reachable assertion as CVE-2016-9397 (bug 1396979). Upstream bug report is: https://github.com/mdadams/jasper/issues/56 The issue remains unfixed in the current upstream version 2.0.14. |