PT-2025-32527 · Jasper+1 · Jasper+1
Nipc-Cxd
·
Published
2025-08-11
·
Updated
2026-01-30
·
CVE-2025-8835
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
JasPer versions up to 4.2.5
Description:
A vulnerability exists in JasPer due to a null pointer dereference in the
jas image chclrspc function within the Image Color Space Conversion Handler component (file src/libjasper/base/jas image.c). This manipulation can be exploited on the local host. The exploit for this issue has been publicly disclosed.Recommendations:
Apply the patch with identifier bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52 to resolve this issue.
Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jasper
Suse