Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ghostscript | Jul 30, 2024 | Oct 2, 2008 |
| Freebsd | — | Upgrade jasper | Dec 10, 2025 | Apr 18, 2013 |
| Gentoo Linux | — | Upgrade media-libs/jasper. | Oct 30, 2017 | Oct 2, 2008 |
| Suse | — | Upgrade libjasper7Upgrade libjasper-develUpgrade libjasper1Upgrade libjasper4Upgrade libjasper-32bitUpgrade libjasper1-32bitUpgrade jasperUpgrade libjasperUpgrade libjasper-x86 | Dec 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libjasper1Upgrade libjasper-1.701-1Upgrade libgs8 | Nov 8, 2024 | Oct 2, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub