CVE-2022-2963

Severity
7.5HIGH
EPSS
0.2%
top 56.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateJul 15

Description

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5jasperjasper 3.0.6

Also affects: Fedora 36, Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

4
GHSA
cookiejar Regular Expression Denial of Service via Cookie.parse function2023-01-18
CVEList
CVE-2022-2963: A vulnerability found in jasper2022-10-14
OSV
CVE-2022-2963: A vulnerability found in jasper2022-10-14
GHSA
GHSA-g89h-fpvv-hmhh: A vulnerability found in jasper2022-10-14

📋Vendor Advisories

2
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (JasPer) — CVE-2022-29632023-07-15
Red Hat
jasper: memory leaks in function cmdopts_parse2022-07-20