Vulnerability Database
Blog
FAQ
Docs
CVE-2018-20570
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-20570
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20570.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-20570
Related
DLA-1628-1
SUSE-SU-2020:2689-1
SUSE-SU-2020:2690-1
UBUNTU-CVE-2018-20570
openSUSE-SU-2020:1517-1
openSUSE-SU-2020:1523-1
openSUSE-SU-2024:10869-1
Published
2018-12-28T16:29:05Z
Modified
2025-01-14T07:29:17.907926Z
Severity
6.5 (Medium)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
[none]
Details
jp2
encode in jp2/jp2
enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
References
https://github.com/mdadams/jasper/issues/191
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00082.html
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00085.html
https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html
https://www.oracle.com/security-alerts/cpuapr2020.html
Affected packages
Git
/
github.com/mdadams/jasper
Affected ranges
Type
GIT
Repo
https://github.com/mdadams/jasper
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
1a36ca39da535af2e67848f5f43ffd657746e632
Affected versions
Other
mdadams-clang-issue
version-1.*
version-1.900.1
version-1.900.10
version-1.900.11
version-1.900.12
version-1.900.13
version-1.900.14
version-1.900.15
version-1.900.16
version-1.900.17
version-1.900.18
version-1.900.19
version-1.900.2
version-1.900.20
version-1.900.21
version-1.900.22
version-1.900.23
version-1.900.24
version-1.900.25
version-1.900.26
version-1.900.27
version-1.900.28
version-1.900.29
version-1.900.3
version-1.900.30
version-1.900.31
version-1.900.4
version-1.900.5
version-1.900.6
version-1.900.7
version-1.900.8
version-1.900.9
version-2.*
version-2.0.0
version-2.0.0-beta.1
version-2.0.0-beta.2
version-2.0.1
version-2.0.10
version-2.0.11
version-2.0.12
version-2.0.13
version-2.0.14
version-2.0.2
version-2.0.3
version-2.0.4
version-2.0.5
version-2.0.6
version-2.0.7
version-2.0.8
version-2.0.9
CVE-2018-20570 - OSV