jasper: memory leaks in function cmdopts_parse
Published Oct 14, 2022
7.5
HIGHCVSS 3.1
EPSS 1.40%
Description
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
Affected products
- Vendor n/a Product Jasper Defaultn/a
- Version jasper 3.0.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Jasper | n/a |
|
Configuration 1
- 3.0.6
Configuration 2
- 36
Configuration 3
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
jasper
Will not fix
Red Hat Enterprise Linux 9
jasper
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | jasper | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | jasper | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has determined this vulnerability to be of moderate impact as the memory leak occurs when cmdline parsing fails and causes the process to terminate right away without releasing the memory, leading to the leak. It would take repeated invocations to exhaust system memory and potentially cause service degradation over time.
References (5)
- https://access.redhat.com/security/cve/CVE-2022-2963 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2118587 Issue TrackingPatchThird Party Advisory
- https://github.com/jasper-software/jasper/issues/332 ExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2963
- https://www.cve.org/CVERecord?id=CVE-2022-2963
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2963 | Third Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2118587 | Issue TrackingPatchThird Party Advisory | |
| https://github.com/jasper-software/jasper/issues/332 | ExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2963 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2963 |
Change history (0)
No recorded changes yet.