Metrics
Affected Vendors & Products
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jasper Project
Jasper Project jasper |
|
Vendors & Products |
Jasper Project
Jasper Project jasper |
Mon, 11 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 11 Aug 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8308060d3fbc1da10353ac8a95c8ea60eba9c25a. It is recommended to apply a patch to fix this issue. | |
Title | JasPer JPEG2000 File jpc_dec.c jpc_dec_dump use after free | |
Weaknesses | CWE-119 CWE-416 |
|
References |
|
|
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-11T08:02:07.784Z
Updated: 2025-08-11T19:56:29.410Z
Reserved: 2025-08-10T11:14:54.230Z
Link: CVE-2025-8837

Updated: 2025-08-11T19:46:06.281Z

Status : Awaiting Analysis
Published: 2025-08-11T08:15:26.887
Modified: 2025-08-11T20:15:28.987
Link: CVE-2025-8837

No data.