CVE-2022-2963

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
jasper_projectjasper
3.0.6
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jasper
focal
dne
jammy
dne
mantic
dne
noble
dne
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libjasper-devel
suse enterprise desktop 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise desktop 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP4
2.0.14-150000.3.28.1
fixed
suse enterprise server 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP7
4.0.0-150600.2.2
fixed
libjasper1
suse enterprise sap 12 SP5
1.900.14-195.34.1
fixed
suse enterprise server 12 SP3
1.900.14-195.34.1
fixed
suse enterprise server 12 SP5
1.900.14-195.34.1
fixed
libjasper1-32bit
suse enterprise sap 12 SP5
1.900.14-195.34.1
fixed
suse enterprise server 12 SP3
1.900.14-195.34.1
fixed
suse enterprise server 12 SP5
1.900.14-195.34.1
fixed
libjasper4
suse enterprise server 15 SP4
2.0.14-150000.3.28.1
fixed
libjasper7
suse enterprise desktop 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise desktop 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise sap 15 SP7
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP6
4.0.0-150600.2.2
fixed
suse enterprise server 15 SP7
4.0.0-150600.2.2
fixed