CVE-2018-19541

HIGH

JasPer <2.0.16 - Buffer Overflow

Title source: llm
STIX 2.1

Description

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer over-read of size 8 in the function jas_image_depalettize in libjasper/base/jas_image.c.

References (5)

Core 5
Core References
Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html
Exploit, Third Party Advisory x_refsource_misc
https://github.com/mdadams/jasper/issues/182

Scores

CVSS v3 8.8
EPSS 0.0118
EPSS Percentile 78.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-125
Status published
Products (7)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
debian/debian_linux 8.0
jasper_project/jasper 2.0.14
suse/linux_enterprise_desktop 12 sp3 (2 CPE variants)
suse/linux_enterprise_server 11 sp3 (2 CPE variants)
suse/linux_enterprise_server 12 sp1 (2 CPE variants)
Published Nov 26, 2018
Tracked Since Feb 18, 2026