First published: Mon Nov 26 2018(Updated: )
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer overflow of size 1 in the function jas_icctxtdesc_input in libjasper/base/jas_icc.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Project Jasper | =2.0.14 | |
SUSE Linux Enterprise Desktop | =12-sp3 | |
SUSE Linux Enterprise Desktop | =12-sp4 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Server | =12-sp2 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19540 is a vulnerability discovered in JasPer that affects versions 1.900.8 to 1.900.31, 2.0.0 to 2.0.3.
CVE-2018-19540 has a severity rating of 8.8 (high).
CVE-2018-19540 affects JasPer versions 1.900.8 to 1.900.31, 2.0.0 to 2.0.3.
To fix CVE-2018-19540, update to a patched version of JasPer.
More information about CVE-2018-19540 can be found at the following references: [link1], [link2], [link3].