There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
| Software | From | Fixed in |
|---|---|---|
| jasper_project / jasper | 2.0.12 | 2.0.12.x |
| fedoraproject / fedora | 32 | 32.x |
| fedoraproject / fedora | 33 | 33.x |
| debian / debian_linux | 8.0 | 8.0.x |