A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
References
Link | Resource |
---|---|
https://github.com/jasper-software/jasper/issues/265 | Exploit Issue Tracking Patch Third Party Advisory |
https://github.com/jasper-software/jasper/commit/41f214b121b837fa30d9ca5f2430212110f5cd9b | Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JYVCFVTVPL66OS7LCNLUSYCMYQAVWXMM/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRZFZSJ4UVLLMXSKHR455TAC2SD3TOHI/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JSXESYUHMO522Z3RHXOQ2SJNWP3XTO67/ | Mailing List Third Party Advisory |
Information
Published : 2021-02-23 12:15
Updated : 2021-03-23 18:04
NVD link : CVE-2021-26927
Mitre link : CVE-2021-26927
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
jasper_project
- jasper
fedoraproject
- fedora