Description
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-20327 | There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability. |
Ubuntu USN |
USN-4688-1 | JasPer vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T16:25:43.579Z
Reserved: 2020-10-27T00:00:00.000Z
Link: CVE-2020-27828
No data.
Status : Modified
Published: 2020-12-11T04:15:11.830
Modified: 2024-11-21T05:21:53.437
Link: CVE-2020-27828
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN