CVE-2015-5203

Severity
5.5MEDIUM
EPSS
0.6%
top 30.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 14

Description

Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Ubuntujasper< 1.900.1-14ubuntu3.5+1
NVDjasper_project/jasper1.900.17
NVDopensuse/leap42.2
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 23, 24, 25

🔴Vulnerability Details

3
GHSA
GHSA-8p3p-rp99-mrhw: Double free vulnerability in the jasper_image_stop_load function in JasPer 12022-05-14
OSV
CVE-2015-5203: Double free vulnerability in the jasper_image_stop_load function in JasPer 12017-08-02
CVEList
CVE-2015-5203: Double free vulnerability in the jasper_image_stop_load function in JasPer 12017-08-02

📋Vendor Advisories

2
Ubuntu
JasPer vulnerabilities2018-06-27
Red Hat
jasper: integer overflow in jas_image_cmpt_create()2015-08-16

💬Community

5
Bugzilla
CVE-2015-5203 mingw-jasper: jasper: double free in jasper_image_stop_load() [fedora-all]2015-08-17
Bugzilla
CVE-2015-5203 jasper: integer overflow in jas_image_cmpt_create()2015-08-17
Bugzilla
CVE-2015-5203 mingw-jasper: jasper: double free in jasper_image_stop_load() [epel-7]2015-08-17
Bugzilla
CVE-2015-5203 jasper: double free in jasper_image_stop_load() [fedora-all]2015-08-17
Bugzilla
CVE-2015-5203 jasper: double free in jasper_image_stop_load() [epel-5]2015-08-17