There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
| Product | Vendor | Version |
|---|---|---|
| jasper | n/a | < 0f62358ce85b2d4c949ef1b648be01b29cec667a |