CVE-2025-8835: JasPer Image Color Space Conversion jas_image.c jas_image_chclrspc null pointer dereference
A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jasimagechclrspc of the file src/libjasper/base/jasimage.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of the patch is bb7d62bd0a2a8e0e1fdb4d603f3305f955158c52. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8835?
CVE-2025-8835 has a medium severity rating due to the potential for null pointer dereference.
How do I fix CVE-2025-8835?
To fix CVE-2025-8835, update JasPer to version 4.2.6 or later where the vulnerability is patched.
What versions of JasPer are affected by CVE-2025-8835?
CVE-2025-8835 affects versions of JasPer up to and including 4.2.5.
What component is affected in CVE-2025-8835?
CVE-2025-8835 affects the Image Color Space Conversion Handler in the JasPer library.
What type of vulnerability is CVE-2025-8835?
CVE-2025-8835 is classified as a null pointer dereference vulnerability.