yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-31744
Component Overview
Vulnerability Overview
Name
CVE-2024-31744
Source
NVD (
link
)
Debian (
link
)
Description
In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.
CWEs
CWE-617
Published Date
Apr 19, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
jasper
Patched
Vulnerability Ratings
#
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
jasper
buildroot
2025.02.x
2.0.33
Not Affected
jasper
buildroot
master
4.2.9
Not Affected
jasper
yocto
kirkstone
2.0.33
Not Affected
jasper
yocto
master
4.2.9
Not Affected
Resolved with patches
#
jasper (yocto:scarthgap)
#
Title
Author
Resolve
1
Fixes #381.
Michael Adams <mdadams@ece.uvic.ca>
CVE-2024-31744