Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-27828

Опубликовано: 11 дек. 2020
Источник: debian
EPSS Низкий

Описание

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jasperremovedpackage

Примечания

  • https://github.com/jasper-software/jasper/issues/252

  • https://github.com/jasper-software/jasper/pull/253

EPSS

Процентиль: 71%
0.01388
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

CVSS3: 7.8
redhat
почти 6 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

CVSS3: 7.8
nvd
почти 6 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

CVSS3: 7.8
github
больше 4 лет назад

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.

suse-cvrf
больше 5 лет назад

Security update for jasper

EPSS

Процентиль: 71%
0.01388
Низкий