CVE-2021-26927

Severity
5.5MEDIUM
EPSS
0.1%
top 75.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateMay 24

Description

A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDjasper_project/jasper< 2.0.25
CVEListV5jasperbefore 2.0.25

Also affects: Fedora 32, 33, 34

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9768-8435-chr8: A flaw was found in jasper before 22022-05-24
OSV
CVE-2021-26927: A flaw was found in jasper before 22021-02-23
CVEList
CVE-2021-26927: A flaw was found in jasper before 22021-02-23

📋Vendor Advisories

2
Microsoft
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.2021-02-09
Red Hat
jasper: NULL pointer dereference in jp2_decode() in jp2_dec.c2021-01-29