CVE-2007-2721

N/A Unknown
Published: May 16, 2007 Modified: April 23, 2026
View on NVD

Description

The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413033
Source: cve@mitre.org
Exploit Vendor Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413041
Source: cve@mitre.org
Exploit Vendor Advisory
http://osvdb.org/36137
Source: cve@mitre.org
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413033
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413041
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=413041%3Bmsg=88
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/36137
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25287
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25703
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26516
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27319
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27489
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/39505
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2010/dsa-2036
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:129
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:208
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:209
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDVSA-2009:142
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDVSA-2009:164
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2009-0012.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/24052
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-501-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-501-2
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2010/0912
Source: af854a3a-2127-422b-91ae-364da2661108

44 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
10.1%
93th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

jasper_jpeg-2000