CVE-2017-14232: Flif
Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file.
Affected products
- Flif Flif: version 0.3 only
- Jasper Project Jasper: up to and including 2.0.16
Published 2019-08-15. Last modified 2026-06-17.