Logo
vulnerabilityCVE-2025-8837
Name
CVE-2025-8837
Source
NVD ( link)Debian ( link)
Description
A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named 8308060d3fbc1da10353ac8a95c8ea60eba9c25a. It is recommended to apply a patch to fix this issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
jasper
Patched

Vulnerability Ratings#


1.9
CVSSv4
5.3
CVSSv31
7.8
CVSSv31
4.3
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
4.2.9
Not Affected
yocto
kirkstone
2.0.33
Patched
yocto
master
4.2.9
Not Affected
yocto
scarthgap
4.1.2
Patched

Resolved with patches#


jasper (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fixes #402, #403.
Michael Adams <mdadams@ece.uvic.ca>
CVE-2025-8837

jasper (yocto:kirkstone)

#
Title
Author
Resolve
1
Fixes #402, #403.
Michael Adams <mdadams@ece.uvic.ca>
CVE-2025-8837

jasper (yocto:scarthgap)

#
Title
Author
Resolve
1
Fixes #402, #403.
Michael Adams <mdadams@ece.uvic.ca>
CVE-2025-8837