CVE-2025-8837

EUVD-2025-24131
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8308060d3fbc1da10353ac8a95c8ea60eba9c25a. It is recommended to apply a patch to fix this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
jasper_projectjasper
𝑥
≤ 4.2.5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jasper
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libjasper-devel
suse enterprise desktop 15 SP6
4.2.8-150600.4.5.1
fixed
suse enterprise desktop 15 SP7
4.2.8-150600.4.5.1
fixed
suse enterprise sap 15 SP6
4.2.8-150600.4.5.1
fixed
suse enterprise sap 15 SP7
4.2.8-150600.4.5.1
fixed
suse enterprise server 15 SP4
2.0.14-150000.3.37.1
fixed
suse enterprise server 15 SP6
4.2.8-150600.4.5.1
fixed
suse enterprise server 15 SP7
4.2.8-150600.4.5.1
fixed
libjasper1
suse enterprise server 12 SP3
1.900.14-195.43.1
fixed
libjasper1-32bit
suse enterprise server 12 SP3
1.900.14-195.43.1
fixed
libjasper4
suse enterprise server 15 SP4
2.0.14-150000.3.37.1
fixed
libjasper7
suse enterprise desktop 15 SP6
4.2.8-150600.4.5.1
fixed
suse enterprise desktop 15 SP7
4.2.8-150600.4.5.1
fixed
suse enterprise sap 15 SP6
4.2.8-150600.4.5.1
fixed
suse enterprise sap 15 SP7
4.2.8-150600.4.5.1
fixed
suse enterprise server 15 SP6
4.2.8-150600.4.5.1
fixed
suse enterprise server 15 SP7
4.2.8-150600.4.5.1
fixed