CVE-2018-20622 (NVD)

2018-12-31

JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.

Products Debian_linux, Jasper
Type Resource Management Errors (CWE-399)
First patch - None (likely due to unavailable code)
Links https://github.com/mdadams/jasper/issues/193
http://www.securityfocus.com/bid/106373
https://lists.debian.org/debian-lts-announce/2019/01/msg00003.html