Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
| Software | From | Fixed in |
|---|---|---|
| fedoraproject / fedora | 25 | 25.x |
| fedoraproject / fedora | 24 | 24.x |
| fedoraproject / fedora | 23 | 23.x |
| opensuse_project / leap | 42.1 | 42.1.x |
| opensuse / leap | 42.2 | 42.2.x |
| opensuse / opensuse | 13.1 | 13.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |
| jasper_project / jasper | - | 1.900.1.x |