MEDIUM 5.5 Microsoft

CVE-2021-3272

jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.

Microsoft Security Update 2021-Jan: jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.

Affected Products

References

Published: 2021-01-12 · Source: Microsoft · Feed updated: 2026-09-07
This medium severity vulnerability with a CVSS score of 5.5 was published on 2021-01-12 via Microsoft. Affected: cbl2 jasper 2.0.32-2 on CBL Mariner 2.0.
vulnfeed aggregates 10539 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.