Vulnerability Description
A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jasper Project | Jasper | < 2.0.25 |
| Fedoraproject | Fedora | 32 |
Related Weaknesses (CWE)
References
- https://github.com/jasper-software/jasper/commit/41f214b121b837fa30d9ca5f2430212PatchThird Party Advisory
- https://github.com/jasper-software/jasper/issues/264ExploitIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://github.com/jasper-software/jasper/commit/41f214b121b837fa30d9ca5f2430212PatchThird Party Advisory
- https://github.com/jasper-software/jasper/issues/264ExploitIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2021-26926?
CVE-2021-26926 is a vulnerability with a CVSS score of 7.1 (HIGH). A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.
How severe is CVE-2021-26926?
CVE-2021-26926 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26926?
Check the references section above for vendor advisories and patch information. Affected products include: Jasper Project Jasper, Fedoraproject Fedora.