CVE Vulnerabilities

CVE-2015-5203

Double Free

Published: Aug 02, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
7 MODERATE
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
FedoraFedoraproject23 (including)23 (including)
FedoraFedoraproject24 (including)24 (including)
FedoraFedoraproject25 (including)25 (including)
Red Hat Enterprise Linux 6RedHatjasper-0:1.900.1-21.el6_9*
Red Hat Enterprise Linux 7RedHatjasper-0:1.900.1-30.el7_3*
JasperUbuntuesm-infra/xenial*
JasperUbuntuprecise*
JasperUbuntutrusty*
JasperUbuntuvivid*
JasperUbuntuvivid/stable-phone-overlay*
JasperUbuntuwily*
JasperUbuntuxenial*
JasperUbuntuyakkety*

Potential Mitigations

References