First published: Wed Oct 31 2018(Updated: )
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Project Jasper | =2.0.14 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Debian Debian Linux | =8.0 | |
SUSE Linux Enterprise Desktop | =12-sp3 | |
SUSE Linux Enterprise Desktop | =12-sp4 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Server | =12-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue in JasPer is CVE-2018-18873.
The severity level of CVE-2018-18873 is medium with a severity value of 5.5.
CVE-2018-18873 affects JasPer version 2.0.14 and Ubuntu Linux versions 14.04 and 16.04, Debian Linux version 8.0, and SUSE Linux Enterprise Desktop versions 12-sp3 and 12-sp4.
The CWE ID of CVE-2018-18873 is 476.
Yes, there are references available for CVE-2018-18873. You can find them at the following links: [link1](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00082.html), [link2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00085.html), [link3](https://github.com/mdadams/jasper/issues/184).