JasPer is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
JasPer 2.0.8 is vulnerable; prior versions may also be affected.
Information
Debian Linux 6.0 sparc
Debian Linux 6.0 s/390
Debian Linux 6.0 powerpc
Debian Linux 6.0 mips
Debian Linux 6.0 ia-64
Debian Linux 6.0 ia-32
Debian Linux 6.0 arm
Debian Linux 6.0 amd64
Exploit
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
References:
- JasPer Homepage (Micheal Adams)
- jasper-2.0.8 Heap-Use-After-Free due to not setting related pointers to be null (JasPer)