rpm package
suse/jasper&distro=SUSE Linux Enterprise Server 12 SP5
pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5
Vulnerabilities (27)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-31744 | Hig | 7.5 | < 1.900.14-195.40.1 | 1.900.14-195.40.1 | Apr 19, 2024 | In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file. | |
| CVE-2023-51257 | — | < 1.900.14-195.37.1 | 1.900.14-195.37.1 | Jan 16, 2024 | An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code. | ||
| CVE-2022-2963 | — | < 1.900.14-195.34.1 | 1.900.14-195.34.1 | Oct 14, 2022 | A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault. | ||
| CVE-2021-27845 | — | < 1.900.14-195.28.1 | 1.900.14-195.28.1 | Jul 15, 2021 | A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c | ||
| CVE-2021-3467 | — | < 1.900.14-195.31.1 | 1.900.14-195.31.1 | Mar 25, 2021 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened. | ||
| CVE-2021-3443 | — | < 1.900.14-195.31.1 | 1.900.14-195.31.1 | Mar 25, 2021 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened. | ||
| CVE-2021-26927 | — | < 1.900.14-195.31.1 | 1.900.14-195.31.1 | Feb 23, 2021 | A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. | ||
| CVE-2021-26926 | — | < 1.900.14-195.31.1 | 1.900.14-195.31.1 | Feb 23, 2021 | A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash. | ||
| CVE-2021-3272 | — | < 1.900.14-195.25.1 | 1.900.14-195.25.1 | Jan 27, 2021 | jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components. | ||
| CVE-2020-27828 | — | < 1.900.14-195.25.1 | 1.900.14-195.25.1 | Dec 11, 2020 | There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability. | ||
| CVE-2018-20622 | — | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Dec 31, 2018 | JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. | ||
| CVE-2018-20570 | — | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Dec 28, 2018 | jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read. | ||
| CVE-2018-19543 | — | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. | ||
| CVE-2018-19139 | — | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Nov 9, 2018 | An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c. | ||
| CVE-2018-18873 | — | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Oct 31, 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c. | ||
| CVE-2018-9154 | — | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | May 4, 2018 | There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745. | ||
| CVE-2018-9252 | — | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Apr 4, 2018 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c. | ||
| CVE-2017-14132 | Med | 6.5 | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Sep 4, 2017 | JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, | |
| CVE-2017-9782 | Med | 5.5 | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Jun 21, 2017 | JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c. | |
| CVE-2016-9557 | Med | 5.5 | < 1.900.14-195.22.1 | 1.900.14-195.22.1 | Mar 23, 2017 | Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file. |
- affected < 1.900.14-195.40.1fixed 1.900.14-195.40.1
In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.
- CVE-2023-51257Jan 16, 2024affected < 1.900.14-195.37.1fixed 1.900.14-195.37.1
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
- CVE-2022-2963Oct 14, 2022affected < 1.900.14-195.34.1fixed 1.900.14-195.34.1
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
- CVE-2021-27845Jul 15, 2021affected < 1.900.14-195.28.1fixed 1.900.14-195.28.1
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c
- CVE-2021-3467Mar 25, 2021affected < 1.900.14-195.31.1fixed 1.900.14-195.31.1
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
- CVE-2021-3443Mar 25, 2021affected < 1.900.14-195.31.1fixed 1.900.14-195.31.1
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
- CVE-2021-26927Feb 23, 2021affected < 1.900.14-195.31.1fixed 1.900.14-195.31.1
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
- CVE-2021-26926Feb 23, 2021affected < 1.900.14-195.31.1fixed 1.900.14-195.31.1
A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.
- CVE-2021-3272Jan 27, 2021affected < 1.900.14-195.25.1fixed 1.900.14-195.25.1
jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.
- CVE-2020-27828Dec 11, 2020affected < 1.900.14-195.25.1fixed 1.900.14-195.25.1
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
- CVE-2018-20622Dec 31, 2018affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
- CVE-2018-20570Dec 28, 2018affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
- CVE-2018-19543Nov 26, 2018affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
- CVE-2018-19139Nov 9, 2018affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
- CVE-2018-18873Oct 31, 2018affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
- CVE-2018-9154May 4, 2018affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745.
- CVE-2018-9252Apr 4, 2018affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.
- affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4,
- affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.
- affected < 1.900.14-195.22.1fixed 1.900.14-195.22.1
Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.
Page 1 of 2