Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-27828

Опубликовано: 11 дек. 2020
Источник: debian
EPSS Низкий

Описание

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jasperremovedpackage

Примечания

  • https://github.com/jasper-software/jasper/issues/252

  • https://github.com/jasper-software/jasper/pull/253

EPSS

Процентиль: 40%
0.00181
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

CVSS3: 7.8
redhat
около 5 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

CVSS3: 7.8
nvd
около 5 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

CVSS3: 7.8
github
больше 3 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

suse-cvrf
почти 5 лет назад

Security update for jasper

EPSS

Процентиль: 40%
0.00181
Низкий