« List of all CVEs

CVE-2021-3467

Published: 3/25/2021 Last updated: 8/3/2024 Reserved: 3/24/2021

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

grib

Products affected (1)

Product Vendor Version
jasper n/a <= 6.1.*

References (4)