cbcvebase.
CVE-2007-2721
published 2007-05-16

CVE-2007-2721: The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a…

PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.27%
81.1th percentile
The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.

Affected

6 ranges
VendorProductVersion rangeFixed in
artifexghostscript>= 0 < 8.61.dfsg.1~svn8187-1.18.61.dfsg.1~svn8187-1.1
artifexghostscript>= 0 < 8.61.dfsg.1~svn8187-1.18.61.dfsg.1~svn8187-1.1
artifexghostscript>= 0 < 8.61.dfsg.1~svn8187-1.18.61.dfsg.1~svn8187-1.1
artifexghostscript>= 0 < 8.61.dfsg.1~svn8187-1.18.61.dfsg.1~svn8187-1.1
debianghostscript< ghostscript 8.61.dfsg.1~svn8187-1.1 (bookworm)ghostscript 8.61.dfsg.1~svn8187-1.1 (bookworm)
jasper_jpeg-2000jasper_jpeg-2000<= 1.701.1

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.