CVE-2024-31744

EUVD-2024-29617
In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
jasper_projectjasper
4.2.2
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jasper
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libjasper-devel
suse enterprise desktop 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise desktop 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP2
2.0.14-150000.3.34.1
fixed
suse enterprise sap 15 SP3
2.0.14-150000.3.34.1
fixed
suse enterprise sap 15 SP4
2.0.14-150000.3.34.1
fixed
suse enterprise sap 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP2
2.0.14-150000.3.34.1
fixed
suse enterprise server 15 SP3
2.0.14-150000.3.34.1
fixed
suse enterprise server 15 SP4
2.0.14-150000.3.34.1
fixed
suse enterprise server 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP7
4.0.0-150600.2.2
fixed
libjasper1
suse enterprise sap 12 SP5
1.900.14-195.40.1
fixed
suse enterprise server 12 SP3
1.900.14-195.40.1
fixed
suse enterprise server 12 SP5
1.900.14-195.40.1
fixed
libjasper1-32bit
suse enterprise sap 12 SP5
1.900.14-195.40.1
fixed
suse enterprise server 12 SP3
1.900.14-195.40.1
fixed
suse enterprise server 12 SP5
1.900.14-195.40.1
fixed
libjasper4
suse enterprise sap 15 SP2
2.0.14-150000.3.34.1
fixed
suse enterprise sap 15 SP3
2.0.14-150000.3.34.1
fixed
suse enterprise sap 15 SP4
2.0.14-150000.3.34.1
fixed
suse enterprise server 15 SP2
2.0.14-150000.3.34.1
fixed
suse enterprise server 15 SP3
2.0.14-150000.3.34.1
fixed
suse enterprise server 15 SP4
2.0.14-150000.3.34.1
fixed
libjasper7
suse enterprise desktop 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise desktop 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP7
4.0.0-150600.2.2
fixed