There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
https://bugzilla.redhat.com/show_bug.cgi?id=1485287
https://lists.debian.org/debian-lts-announce/2018/11/msg00023.html