Red Hat Bugzilla – Bug 1488960
CVE-2017-13747 jasper: reachable assertion in jpc_floorlog2()
Last modified: 2018-07-18 11:30:47 EDT
There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a denial of service attack. Product bug: https://bugzilla.redhat.com/show_bug.cgi?id=1485282
Created jasper tracking bugs for this issue: Affects: fedora-all [bug 1434464] Created mingw-jasper tracking bugs for this issue: Affects: epel-7 [bug 1434465] Affects: fedora-all [bug 1434467]
This CVE is for the same reachable assertion as CVE-2016-9398 (bug 1396980). Upstream bug report is: https://github.com/mdadams/jasper/issues/71 The issue remains unfixed in the current upstream version 2.0.14.