QID 354893

Date Published: 2023-04-24

QID 354893: Amazon Linux Security Advisory for jasper : ALAS2-2023-2018

A flaw was found in the jasper tool's jpc encoder.
This flaw allows an attacker to craft input provided to jasper, causing an arbitrary out-of-bounds write.
The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. (
( CVE-2020-27828) a flaw was found in jasper before 2.0.25.
An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash. (
( CVE-2021-26926) a flaw was found in jasper before 2.0.25.
A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. (
( CVE-2021-26927) jp2_decode in jp2/jp2_dec.c in libjasper in jasper 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components. (
( CVE-2021-3272) a null pointer dereference flaw was found in the way jasper versions before 2.0.27 handled component references in the jp2 image format decoder.
A specially crafted jp2 image file could cause an application using the jasper library to crash when opened. (
( CVE-2021-3443) a null pointer dereference flaw was found in the way jasper versions before 2.0.26 handled component references in cdef box in the jp2 image format decoder.
( CVE-2021-3467)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2-2023-2018 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ALAS2-2023-2018 amazon linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2023-2018.html