JasPer 'base/jas_malloc.c' Memory Leak Information Disclosure Vulnerability
BID:106373
CVE-2018-20622 |Info
JasPer 'base/jas_malloc.c' Memory Leak Information Disclosure Vulnerability
| Bugtraq ID: | 106373 |
| Class: | Design Error |
| CVE: |
CVE-2018-20622 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2018 12:00AM |
| Updated: | Dec 31 2018 12:00AM |
| Credit: | zerokeeper |
| Vulnerable: |
JasPer JasPer 2.0.14 |
| Not Vulnerable: | |
Discussion
JasPer 'base/jas_malloc.c' Memory Leak Information Disclosure Vulnerability
JasPer is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
JasPer 2.0.14 version is vulnerable; other versions may also be vulnerable.
JasPer is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
JasPer 2.0.14 version is vulnerable; other versions may also be vulnerable.
References
JasPer 'base/jas_malloc.c' Memory Leak Information Disclosure Vulnerability
References:
References:
- JasPer Homepage (Micheal Adams)
- memory leaks in jpc_dec_decodepkts #193 ()