216.73.216.197

CVE-2025-8835

· Published 11/08/2025 07:15 · Modified 12/08/2025 14:15

Labels: CVE-2025-8835 2025-08-11CVE-2025-8835CWE-404[email protected]

Essential information

Published
11/08/2025 07:15
Modified
12/08/2025 14:15
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52. It is recommended to apply a patch to fix this issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jasper / jasper cpe:2.3:a:jasper:jasper:<4.2.5:*:*:*:*:*:*:*

References