CVE-2020-27828: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
Affected products
- Fedoraproject Fedora: version 32 only; version 33 only
- Jasper Project Jasper: before 2.0.23 (fixed in 2.0.23)
Published 2020-12-11. Last modified 2026-06-17.