Memory leak in JasPer - CVE-2022-2963

 

Memory leak in JasPer - CVE-2022-2963

Published: October 20, 2022 / Updated: December 2, 2022


Vulnerability identifier: #VU68550
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2963
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform DoS attack on the target system.

The vulnerability exists due memory leak within the cmdopts_parse() function. A local user can pass specially crafted input to the application and perform denial of service attack.


Affected software

JasPer
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Fedora
InfoSphere Data Architect
Oracle Communications Cloud Native Core Service Communication Proxy
jasper-debugsource
libjasper-devel
libjasper1
libjasper1-debuginfo
libjasper1-32bit
libjasper1-debuginfo-32bit
jasper-debuginfo
libjasper4-32bit-debuginfo
libjasper4-32bit
libjasper4-debuginfo
libjasper4
jasper
mingw-jasper

How to mitigate CVE-2022-2963

Install update from vendor's website.

JasPer - update to 4.0.0
InfoSphere Data Architect - update to 9.2.1
jasper-debugsource - addressed in versions 1.900.14-195.34.1, 2.0.14-150000.3.28.1
libjasper-devel - addressed in versions 1.900.14-195.34.1, 2.0.14-150000.3.28.1
libjasper1 - update to 1.900.14-195.34.1
libjasper1-debuginfo - update to 1.900.14-195.34.1
libjasper1-32bit - update to 1.900.14-195.34.1
libjasper1-debuginfo-32bit - update to 1.900.14-195.34.1
jasper-debuginfo - addressed in versions 1.900.14-195.34.1, 2.0.14-150000.3.28.1
libjasper4-32bit-debuginfo - update to 2.0.14-150000.3.28.1
libjasper4-32bit - update to 2.0.14-150000.3.28.1
libjasper4-debuginfo - update to 2.0.14-150000.3.28.1
libjasper4 - update to 2.0.14-150000.3.28.1
jasper - update to 2.0.14-150000.3.28.1
mingw-jasper - update to 3.0.6-2.fc37

External References

Related Security Bulletins