CVE-2020-27828
11.12.2020, 04:15
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jasper_project | jasper | 𝑥 < 2.0.23 |
𝑥
= Vulnerable software versions
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libjasper-devel |
| ||||||||||||||||
| libjasper1 |
| ||||||||||||||||
| libjasper1-32bit |
| ||||||||||||||||
| libjasper4 |
| ||||||||||||||||
| libjasper7 |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References