There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
References
Configurations
History
No history.
Information
Published : 2020-12-11 04:15
Updated : 2023-11-07 03:21
NVD link : CVE-2020-27828
Mitre link : CVE-2020-27828
CVE.ORG link : CVE-2020-27828
JSON object : View
Products Affected
fedoraproject
- fedora
jasper_project
- jasper
CWE
CWE-20
Improper Input Validation