PatchSiren cyber security CVE debrief
CVE-2017-5499 Jasper Project CVE debrief
CVE-2017-5499 affects JasPer 1.900.17 and is described by NVD as an integer overflow in libjasper/jpc/jpc_dec.c that can let a crafted file crash the application. NVD classifies the weakness as CWE-190 and assigns CVSS 3.0 5.5 (MEDIUM), with impact limited to availability. The record was published on 2017-03-01 and later modified on 2026-05-13.
- Vendor
- Jasper Project
- Product
- CVE-2017-5499
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-01
- Advisory updated
- 2026-05-13
Who should care
Administrators, maintainers, and developers who use JasPer 1.900.17 or ship libjasper-based image parsing in products that may process untrusted files.
Technical summary
The vulnerable component is libjasper/jpc/jpc_dec.c in JasPer 1.900.17. NVD identifies the flaw as an integer overflow (CWE-190) and associates it with denial of service via application crash when a crafted file is parsed. The NVD CVSS vector is CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, which indicates high availability impact but requires user interaction; this differs from the prose description that mentions remote attackers.
Defensive priority
MEDIUM
Recommended defensive actions
- Inventory systems that include JasPer 1.900.17 or bundled libjasper components.
- Upgrade to a vendor-fixed JasPer release where available.
- Restrict or sandbox processing of untrusted files until patched.
- Monitor for parser crashes or repeated failures in applications that handle Jasper content.
- If the vulnerable component is embedded in a third-party product, track the vendor's remediation guidance and update that product as well.
Evidence notes
Primary evidence comes from the NVD record and CVE record for CVE-2017-5499, which identify JasPer 1.900.17, libjasper/jpc/jpc_dec.c, CWE-190, and CVSS 3.0 5.5. The source reference set also includes a Gentoo advisory about multiple crashes and two openSUSE security announcements. Note that the narrative description says 'remote attackers,' while the CVSS vector indicates a local, user-interaction-required attack path; this discrepancy is visible in the supplied source corpus.
Official resources
-
CVE-2017-5499 CVE record
CVE.org
-
CVE-2017-5499 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
- Source reference
- Source reference
-
Mitigation or vendor reference
[email protected] - Exploit, Third Party Advisory
CVE-2017-5499 was published on 2017-03-01 and modified on 2026-05-13 in the supplied NVD record. PatchSiren timing is not used as the issue date.