A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jasper-develUpgrade jasper-libsUpgrade jasper-debuginfoUpgrade jasper-utilsUpgrade jasper | Apr 21, 2023 | Mar 25, 2021 |
| Amazon_linux | — | Upgrade jasper | Apr 21, 2023 | Mar 25, 2021 |
| Huawei Euleros 2_0_sp2 | — | Upgrade jasper-libs | Sep 16, 2021 | Mar 25, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade jasper-libs | Apr 30, 2021 | Mar 25, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 25, 2021 |
| Suse | — | Upgrade libjasper-develUpgrade jasperUpgrade libjasper1-32bitUpgrade libjasper4Upgrade libjasper1Upgrade libjasper4-32bit | Oct 26, 2022 | Mar 25, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 25, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub