CVE-2018-9252

Description

A vulnerability was found in Jasper due to a flaw in the jpc_abstorelstepsize function within libjasper/jpc/jpc_enc.c, where an attacker can cause a denial of service, leading to the application crashing when triggered by specially crafted input.

Statement

This vulnerability is rated as a moderate because it allows denial of service due to a reachable assertion in the jpc_abstorelstepsize function within libjasper/jpc/jpc_enc.c. Processing specially crafted input may trigger this issue, causing an application crash and affecting availability, it does not lead to code execution.

The following products are now in Extended Life Phase of the support and maintenance life cycle.

  • Red Hat Enterprise Linux 5
  • Red Hat Enterprise Virtualization 3 The following products are now in Maintenance Phase 2 of the support and maintenance life cycle.
  • Red Hat Enterprise Linux 6 This issue is not currently planned to be addressed in future updates of these products. For additional information, please refer to the Life Cycle and Update Policies: https://access.redhat.com/support/policy/update_policies/

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.56.5N/A
Attack VectorNetworkNetworkN/A
Attack ComplexityLowLowN/A
Privileges RequiredNoneNoneN/A
User InteractionRequiredRequiredN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

NVD: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart

An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.

Frequently Asked Questions

Want to get errata notifications? Sign up here.