There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
https://security.gentoo.org/glsa/201908-03
https://lists.debian.org/debian-lts-announce/2018/11/msg00023.html