Severity
7.8HIGH
EPSS
0.2%
top 60.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 24

Description

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDjasper_project/jasper< 2.0.23
Ubuntujasper< 1.900.1-debian1-2.4ubuntu1.3
CVEListV5jasperprior to 2.0.23

Also affects: Fedora 32, 33

Patches

🔴Vulnerability Details

4
GHSA
GHSA-x4rf-6444-7fh8: There's a flaw in jasper's jpc encoder in versions prior to 22022-05-24
OSV
jasper vulnerabilities2021-01-11
OSV
CVE-2020-27828: There's a flaw in jasper's jpc encoder in versions prior to 22020-12-11
CVEList
CVE-2020-27828: There's a flaw in jasper's jpc encoder in versions prior to 22020-12-11

📋Vendor Advisories

2
Ubuntu
JasPer vulnerabilities2021-01-11
Red Hat
jasper: Heap-based buffer overflow in cp_create() in jpc_enc.c2020-11-30