PT-2021-17181 · Jasper+6 · Jasper+6

Dgh05T

·

Published

2021-02-09

·

Updated

2024-06-15

·

CVE-2021-26926

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: jasper versions prior to 2.0.25
Description: A flaw was found in the jp2 decode function, which may lead to disclosure of information or program crash due to an out of bounds read issue.
Recommendations: For versions prior to 2.0.25, update to version 2.0.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the jp2 decode function until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4235
ALT-PU-2021-1241
AZL-6491
CESA-2021_4235
CVE-2021-26926
MGASA-2021-0113
OPENSUSE-SU-2022_1479-1
OPENSUSE-SU-2024:13389-1
RHSA-2021:4235
RHSA-2021_4235
RLSA-2021:4235
SUSE-SU-2022:1475-1
SUSE-SU-2022:1479-1
SUSE-SU-2022_1475-1
SUSE-SU-2022_1479-1

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Jasper