Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.0 Base Score: 5.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jasper | Sep 20, 2017 | Apr 13, 2016 |
| Amazon_linux | — | Upgrade jasper | Jun 7, 2017 | Apr 13, 2016 |
| Centos_linux | — | Upgrade jasper-libsUpgrade jasper-debuginfoUpgrade jasper-utilsUpgrade jasper-develUpgrade jasper | May 19, 2017 | Apr 13, 2016 |
| Debian | — | Upgrade jasper | Mar 8, 2016 | Mar 6, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade jasper-libs | Nov 30, 2017 | Apr 13, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade jasper-libs | Nov 30, 2017 | Apr 13, 2016 |
| Oracle_linux | — | Upgrade jasper-develUpgrade jasperUpgrade jasper-libsUpgrade jasper-utils | May 9, 2017 | Mar 3, 2016 |
| Redhat_linux | — | Upgrade jasper-libsUpgrade jasper-develUpgrade jasper-utilsUpgrade jasper-debuginfoUpgrade jasper | May 9, 2017 | Apr 13, 2016 |
| Suse | — | Upgrade libjasper-develUpgrade libjasper-32bitUpgrade libjasperUpgrade libjasper1Upgrade libjasper4Upgrade libjasper-x86Upgrade libjasper1-32bit | Nov 5, 2016 | Apr 13, 2016 |
| Ubuntu | — | Upgrade libjasper1 | Mar 3, 2016 | Mar 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub