An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpcdecdump of the file src/libjasper/jpc/jpcdec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8308060d3fbc1da10353ac8a95c8ea60eba9c25a. It is recommended to apply a patch to fix this issue.
A double free vulnerability was found in memclose in jasstream.c triggered by invoking imginfo command on specially crafted image file.
CVE assignment:
http://www.openwall.com/lists/oss-security/2016/10/16/14
A stack-based buffer overflow vulnerability was found in jasper in jpctsfbgetbands2 function in jpctsfb.c triggered by parsing of a malicious file.
Upstream patch:
https://github.com/mdadams/jasper/commit/1abc2e5a401a4bf1d5ca4df91358ce5df111f495
References:
http://seclists.org/oss-sec/2016/q4/473
Heap-based buffer overflow in the jpcdecdecodepkt function in jpct2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
An assertion failure was possible to trigger in JPCNOMINALGAIN.
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
An assertion failure was used in JPC bitstream code when integer larger than what can be handled is requested.
Upstream patch:
https://github.com/mdadams/jasper/commit/1e84674d95353c64e5c4c0e7232ae86fd6ea813b
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
An assertion test was used when ensuring the component domains are the same for the ICT/RCT in the JPC codec.
Upstream patch:
https://github.com/mdadams/jasper/commit/dee11ec440d7908d1daf69f40a3324b27cf213ba
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
There is a reachable abort in the function jpcdecprocesssot in libjasper/jpc/jpcdec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jasalloc2 return value, a different vulnerability than CVE-2017-13745.
A null pointer dereference was found in the way JasPer decoded certaion JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.
Upstream bug:
https://github.com/mdadams/jasper/issues/109
Upstream fix:
https://github.com/mdadams/jasper/commit/a632c6b54bd4ffc3bebab420e00b7e7688aa3846
JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpcabstorelstepsize in libjasper/jpc/jpcenc.c.
A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jasimagechclrspc of the file src/libjasper/base/jasimage.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52. It is recommended to apply a patch to fix this issue.
The jpcdecprocesssiz function in libjasper/jpc/jpcdec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command.
Divide by zero vulnerability was found in jpcdecprocesssiz triggered by invoking imginfo command on specially crafted file.
Upstream patch:
https://github.com/mdadams/jasper/commit/d8c2604cd438c41ec72aff52c16ebd8183068020
CVE assignment:
http://www.openwall.com/lists/oss-security/2016/10/16/14
The jpcdectilefini function in libjasper/jpc/jpcdec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
jp2decode in jp2/jp2dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.
An issue has been found in JasPer 2.0.14. There is a memory leak in jasmalloc.c when called from jpcunkgetparms in jpccs.c.
An assert that can be triggered by crafted input file was found in jpcdectiledecode().
Upstream patch:
https://github.com/mdadams/jasper/commit/33cc2cfa51a8d0fc3116d16cc1d8fc581b3f9e8d
CVE assignment:
http://seclists.org/oss-sec/2016/q4/216
Last updated 25 August 2025
Last updated 25 August 2025
Last updated 25 August 2025
An assertion failure was found in jasper triggered when tiles lie outside of the image area.
Upstream patch:
https://github.com/mdadams/jasper/commit/ba2b9d000660313af7b692542afbd374c5685865
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Last updated 25 August 2025
The jasmatrixasl function in jasseq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
The jasmatrixbindsub function in jasseq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
The jpcundoroi function in libjasper/jpc/jpcdec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
libjasper/jpc/jpcdec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
The decclnpass function in libjasper/jpc/jpct1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via a crafted image.
libjasper/include/jasper/jasmath.h in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.