There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
References
Information
Published : 2020-12-11 04:15
Updated : 2021-02-03 04:15
NVD link : CVE-2020-27828
Mitre link : CVE-2020-27828
JSON object : View
Products Affected
fedoraproject
- fedora
jasper_project
- jasper
