CVE-2020-27828

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
jasper_projectjasper
𝑥
< 2.0.23
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jasper
bionic
dne
focal
dne
groovy
dne
trusty
dne
xenial
Fixed 1.900.1-debian1-2.4ubuntu1.3
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libjasper-devel
suse enterprise desktop 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise desktop 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP1
2.0.14-3.19.1
fixed
suse enterprise server 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP7
4.0.0-150600.2.2
fixed
libjasper1
suse enterprise sap 12 SP2
1.900.14-195.25.1
fixed
suse enterprise sap 12 SP3
1.900.14-195.25.1
fixed
suse enterprise sap 12 SP4
1.900.14-195.25.1
fixed
suse enterprise sap 12 SP5
1.900.14-195.25.1
fixed
suse enterprise server 12 SP2
1.900.14-195.25.1
fixed
suse enterprise server 12 SP3
1.900.14-195.25.1
fixed
suse enterprise server 12 SP4
1.900.14-195.25.1
fixed
suse enterprise server 12 SP5
1.900.14-195.25.1
fixed
libjasper1-32bit
suse enterprise sap 12 SP2
1.900.14-195.25.1
fixed
suse enterprise sap 12 SP3
1.900.14-195.25.1
fixed
suse enterprise sap 12 SP4
1.900.14-195.25.1
fixed
suse enterprise sap 12 SP5
1.900.14-195.25.1
fixed
suse enterprise server 12 SP2
1.900.14-195.25.1
fixed
suse enterprise server 12 SP3
1.900.14-195.25.1
fixed
suse enterprise server 12 SP4
1.900.14-195.25.1
fixed
suse enterprise server 12 SP5
1.900.14-195.25.1
fixed
libjasper4
suse enterprise server 15 SP1
2.0.14-3.19.1
fixed
libjasper7
suse enterprise desktop 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise desktop 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP7
4.0.0-150600.2.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
jasper-devel
RHEL 8
0:2.0.14-5.el8
fixed
jasper-libs
RHEL 8
0:2.0.14-5.el8
fixed