CVE-2018-20570
Severity
6.5MEDIUM
EPSS
1.0%
top 23.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 28
Latest updateMay 13
Description
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
๐ดVulnerability Details
3๐Vendor Advisories
1๐ฌCommunity
4Bugzillaโถ
CVE-2018-20570 mingw-jasper: jasper: heap-based buffer over-read in jp2_encode in jp2/jp2_enc.c [fedora-all]โ2019-01-09
Bugzillaโถ
CVE-2018-20570 mingw-jasper: jasper: heap-based buffer over-read in jp2_encode in jp2/jp2_enc.c [epel-7]โ2019-01-09
Bugzillaโถ
CVE-2018-20570 jasper: heap-based buffer over-read in jp2_encode in jp2/jp2_enc.c [fedora-all]โ2019-01-09