jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-27T07:29:02

Updated: 2024-08-03T16:53:16.007Z

Reserved: 2021-01-22T00:00:00

Link: CVE-2021-3272

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-27T08:15:10.483

Modified: 2023-11-07T03:37:57.710

Link: CVE-2021-3272

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-01-27T00:00:00Z

Links: CVE-2021-3272 - Bugzilla