Описание
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
Отчет
This vulnerability was rated as LOW severity because it requires the victim to open a specially crafted file. While it does not allow full system compromise, it may lead to the leakage of sensitive information through memory consumption.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | netpbm | Out of support scope | ||
| Red Hat Enterprise Linux 6 | jasper | Out of support scope | ||
| Red Hat Enterprise Linux 7 | jasper | Will not fix | ||
| Red Hat Enterprise Linux 8 | jasper | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a wh ...
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
Уязвимость файла libjasper.a набора библиотек JasPer, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
3.3 Low
CVSS3