Unrated severityNVD Advisory· Published Nov 26, 2018· Updated Aug 5, 2024
CVE-2018-19540
CVE-2018-19540
Description
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer overflow of size 1 in the function jas_icctxtdesc_input in libjasper/base/jas_icc.c.
Affected products
11- osv-coords11 versionspkg:rpm/opensuse/jasper&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/jasper&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/jasper&distro=openSUSE%20Tumbleweedpkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4
< 2.0.14-lp150.2.6.1+ 10 more
- (no CPE)range: < 2.0.14-lp150.2.6.1
- (no CPE)range: < 2.0.14-lp151.4.3.1
- (no CPE)range: < 2.0.33-1.2
- (no CPE)range: < 1.900.14-195.15.1
- (no CPE)range: < 2.0.14-3.8.1
- (no CPE)range: < 2.0.14-3.8.1
- (no CPE)range: < 2.0.14-3.8.1
- (no CPE)range: < 2.0.14-3.8.1
- (no CPE)range: < 1.900.14-195.15.1
- (no CPE)range: < 1.900.14-195.15.1
- (no CPE)range: < 1.900.14-195.15.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.opensuse.org/opensuse-security-announce/2019-10/msg00023.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2019-10/msg00025.htmlmitrevendor-advisoryx_refsource_SUSE
- github.com/mdadams/jasper/issues/182mitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2019/01/msg00003.htmlmitremailing-listx_refsource_MLIST
- www.oracle.com/security-alerts/cpuapr2020.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.