First published: Mon Mar 15 2021(Updated: )
A flaw was found in jasper before 2.0.26. A NULL pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. Reference: <a href="https://github.com/jasper-software/jasper/issues/269">https://github.com/jasper-software/jasper/issues/269</a> Upstream patch: <a href="https://github.com/jasper-software/jasper/commit/f94e7499a8b1471a4905c4f9c9e12e60fe88264b">https://github.com/jasper-software/jasper/commit/f94e7499a8b1471a4905c4f9c9e12e60fe88264b</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Project Jasper | <2.0.27 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =33 | |
redhat/jasper | <2.0.27 | 2.0.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3443 is a vulnerability found in the Jasper library, specifically versions before 2.0.27.
CVE-2021-3443 can cause a crash in an application that uses the Jasper library when opening a specially crafted JP2 image file.
Versions before 2.0.27 of the Jasper library are affected by CVE-2021-3443.
CVE-2021-3443 has a severity value of 5.5, which is considered medium.
To fix CVE-2021-3443, update your Jasper library to version 2.0.27 or later.