NULL pointer dereference in JasPer - CVE-2018-19542
Published: May 3, 2019
JasPer
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error in jp2_decode() function in libjasper/jp2/jp2_dec.c. A remote attacker can create a specially crafted image. pass it to hhe application and perform a denial of service (DoS) attack.
How to mitigate CVE-2018-19542
Sources
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00004.html
- https://github.com/mdadams/jasper/issues/182
- https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html
- https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-19542.html
- https://www.suse.com/security/cve/CVE-2018-19542/