There is an infinite loop in the jpc_dec_tileinit function in jpc/jpc_dec.c of Jasper 2.0.13. It will lead to a remote denial of service attack.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html | |
http://www.securityfocus.com/bid/100861 | vdb entry |
https://github.com/mdadams/jasper/issues/146 | third party advisory |
https://security.gentoo.org/glsa/201908-03 | vendor advisory |