First published: Mon Dec 31 2018(Updated: )
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Project Jasper | =2.0.14 | |
Debian Debian Linux | =8.0 | |
<=6.0.2 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-20622.
The severity of CVE-2018-20622 is medium, with a severity value of 6.5.
CVE-2018-20622 in JasPer could allow a remote attacker to obtain sensitive information, caused by a memory leak when "--output-format jp2" is used.
JasPer 2.0.14, Debian Linux 8.0, IBM RDNG up to version 6.0.6.1, and IBM DOORS Next up to version 7.0 are affected by CVE-2018-20622.
To fix the vulnerability in JasPer, it is recommended to update to a patched version of JasPer.