Description
The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-9pv6-4w7h-vppx: The jpc_qcx_getcompparms function in jpc/jpc_cs↗2022-05-01 ▶ CVEListCVE-2007-2721: The jpc_qcx_getcompparms function in jpc/jpc_cs↗2007-05-16 ▶ OSVCVE-2007-2721: The jpc_qcx_getcompparms function in jpc/jpc_cs↗2007-05-16 ▶ 📋Vendor Advisories
4UbuntuGhostscript vulnerability↗2007-10-22 ▶ Ubuntujasper vulnerability↗2007-08-21 ▶ Red Hatjasper: crash in jpc_qcx_getcompparms↗2007-03-01 ▶ DebianCVE-2007-2721: ghostscript - The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 libra...↗2007 ▶ 💬Community
3BugzillaCVE-2007-2721 jasper: crash in jpc_qcx_getcompparms↗2007-10-23 ▶ BugzillaCVE-2007-2721 jasper crash in jpc_qcx_getcompparms [Fdevel]↗2007-10-23 ▶ BugzillaCVE-2007-2721: jasper DoS, heap corruption↗2007-05-17 ▶