CVE-2018-20622
openSUSE Security Advisory - openSUSE-SU-2020:1523-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
La versión 2.0.14 de JasPer tiene una fuga de memoria en base/jas_malloc.c en libjasper.a cuando se utiliza "--output-format jp2".
An update that fixes 14 vulnerabilities is now available. This update for jasper fixes the following issues. Improved patch for already fixed issue. Fixed assert in calcstepsizes. Validate component depth bit. Check bounds in jas_seq2d_bindsub. Check bounds in jas_seq2d_bindsub. Check bounds in jas_seq2d_bindsub. Fixed heap base overflow in by checking components. Fixed reachable assertion in jpc_abstorelstepsize. Fixed null pointer deref in ras_putdatastd. Fixed mem leaks by registering jpc_unk_destroyparms. Fixed numchans mixup. Fixed heap based buffer over-read in jp2_encode. Fixed memory leak in jas_malloc.c. This update was imported from the SUSE:SLE-15:Update update project.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2018-12-31 CVE Reserved
- 2018-12-31 CVE Published
- 2025-05-06 CVE Updated
- 2025-06-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-772: Missing Release of Resource after Effective Lifetime
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106373 | Third Party Advisory | |
https://github.com/mdadams/jasper/issues/193 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html | Mailing List |
|
https://www.oracle.com/security-alerts/cpuapr2020.html | X_refsource_misc |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jasper Project Search vendor "Jasper Project" | Jasper Search vendor "Jasper Project" for product "Jasper" | 2.0.14 Search vendor "Jasper Project" for product "Jasper" and version "2.0.14" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|