Denial of Service Vulnerability in JasPer JPEG Decoder
CVE-2015-5203

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 August 2017

Summary

A double free vulnerability exists in the jasper_image_stop_load function of JasPer 1.900.17, which can be exploited by remote attackers. By sending a specially crafted JPEG 2000 image file, the vulnerability can lead to a denial of service condition, causing the application to crash. This risk highlights the importance of validating image files and applying patches promptly to mitigate potential threats.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.