« List of all CVEs

CVE-2021-3467

Published: 3/25/2021 Last updated: 8/3/2024 Reserved: 3/24/2021

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

grib

Products affected (1)

Product Vendor Version
jasper n/a < 2ab5e243c2266c841e0f6904fad1514b18eaf510

References (8)