CVE-2018-19543: High severity jasper reports vulnerability
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2decode in libjasper/jp2/jp2dec.c.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19543?
CVE-2018-19543 is a vulnerability in JasPer 2.0.14 that allows for a heap-based buffer over-read.
What is the severity of CVE-2018-19543?
The severity of CVE-2018-19543 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2018-19543?
JasPer 2.0.14, Ubuntu Linux 14.04 and 16.04, Debian Linux 8.0, and SUSE Linux Enterprise Desktop and Server versions 11-sp3, 11-sp4, 12-sp1, and 12-sp2 are affected.
How can I fix CVE-2018-19543?
To fix CVE-2018-19543, update JasPer to version 2.0.15 or later.
Where can I find more information about CVE-2018-19543?
You can find more information about CVE-2018-19543 in the following references: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00082.html), [Link 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00085.html), [Link 3](https://github.com/mdadams/jasper/issues/182).