First published: Thu Jan 28 2021(Updated: )
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Project Jasper | <2.0.25 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
redhat/jasper | <2.0.25 | 2.0.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26927 is a vulnerability in jasper before version 2.0.25 that may lead to a program crash and denial of service due to a null pointer dereference.
CVE-2021-26927 can cause the program to crash and result in a denial of service.
The severity of CVE-2021-26927 is medium (5.5).
Versions before 2.0.25 of jasper are affected by CVE-2021-26927.
To fix CVE-2021-26927, update jasper to version 2.0.25 or later.