7.5

CVE-2022-2963

Exploit
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jasper Project ≫ Jasper Version 3.0.6
Fedoraproject ≫ Fedora Version 36
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.37% 0.695
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://access.redhat.com/security/cve/CVE-2022-2963
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2118587
Patch
Third Party Advisory
Issue Tracking
https://github.com/jasper-software/jasper/issues/332
Third Party Advisory
Exploit
Issue Tracking