CVE-2021-3272: Medium severity Jasper Project Jasper vulnerability
jp2decode in jp2/jp2dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jasperto a version that resolves this vulnerability.Fixed in 2.0.25
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-3272.
What is the title of the vulnerability?
The title of the vulnerability is 'jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.'
What is the severity of CVE-2021-3272?
The severity of CVE-2021-3272 is medium with a severity value of 5.5.
Which software versions are affected by CVE-2021-3272?
JasPer 2.0.24 and Fedora 32 and 33 are affected by CVE-2021-3272.
How can CVE-2021-3272 be fixed?
CVE-2021-3272 can be fixed by upgrading to JasPer version 2.0.25.