PT-2025-32527 · Jasper+1 · Jasper+1

Nipc-Cxd

·

Published

2025-08-11

·

Updated

2026-01-30

·

CVE-2025-8835

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: JasPer versions up to 4.2.5
Description: A vulnerability exists in JasPer due to a null pointer dereference in the jas image chclrspc function within the Image Color Space Conversion Handler component (file src/libjasper/base/jas image.c). This manipulation can be exploited on the local host. The exploit for this issue has been publicly disclosed.
Recommendations: Apply the patch with identifier bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52 to resolve this issue.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-66162
CVE-2025-8835
OPENSUSE-SU-2025:15447-1
OPENSUSE-SU-2026:20138-1
SUSE-SU-2025:03219-1
SUSE-SU-2025:03367-1
SUSE-SU-2025:3947-1
SUSE-SU-2025_03219-1
SUSE-SU-2025_03367-1
SUSE-SU-2026:20200-1

Affected Products

Jasper
Suse