CVE-2021-3443: Fedoraproject Fedora
Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
Affected products
- Fedoraproject Fedora: version 33 only
- Jasper Project Jasper: before 2.0.27 (fixed in 2.0.27)
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only
Published 2021-03-25. Last modified 2026-06-17.