CVE-2021-26926: High severity jasper reports vulnerability
A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2decode function whic may lead to disclosure of information or program crash.
Other sources
A flaw was found in jasper. An out of bounds read issue was found in jp2decode function whic may lead to disclosure of information or program crash.
Upstream issue:
https://github.com/jasper-software/jasper/issues/264
Upstream patch:
https://github.com/jasper-software/jasper/commit/41f214b121b837fa30d9ca5f2430212110f5cd9b
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in jasper?
The vulnerability ID for this flaw in jasper is CVE-2021-26926.
What is the severity of CVE-2021-26926?
The severity of CVE-2021-26926 is high, with a severity value of 7.1.
How does the flaw in jasper before 2.0.25 affect the software?
The flaw in jasper before 2.0.25 can lead to disclosure of information or program crash.
How can I fix the vulnerability CVE-2021-26926?
To fix the vulnerability CVE-2021-26926, you should update jasper to version 2.0.25 or newer.
Where can I find more information about CVE-2021-26926?
You can find more information about CVE-2021-26926 in the following references: [Link 1](https://github.com/jasper-software/jasper/issues/264), [Link 2](https://github.com/jasper-software/jasper/commit/41f214b121b837fa30d9ca5f2430212110f5cd9b), and [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1922320).