Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-40000.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-40000
Upstream
Published
2024-04-19T13:15:13Z
Modified
2026-04-01T05:13:55.705582Z
Summary
CVE-2024-31744 affecting package jasper for versions less than 4.2.1-2
Details

In Jasper 4.2.2, the jpcstreamlistremove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.

References

Affected packages

Azure Linux:3 / jasper

Package

Name
jasper
Purl
pkg:rpm/azure-linux/jasper

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.1-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-40000.json"