First published: Wed Jan 13 2016(Updated: )
A vulnerability was found in the way the JasPer's jpc_pi_nextcprl() function parses certain JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash. Report with the reproducer attached: <a href="http://seclists.org/oss-sec/2016/q1/84">http://seclists.org/oss-sec/2016/q1/84</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/jasper | ||
redhat/jasper | <1.900.2 | 1.900.2 |
Jasper Reports | =1.900.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1867 is considered a high severity vulnerability due to its potential to crash applications processing vulnerable JPEG 2000 files.
To fix CVE-2016-1867, update your JasPer package to version 1.900.2 or later if you are using Red Hat, or ensure your Debian installation is patched.
Applications using the JasPer library to process JPEG 2000 images are affected by CVE-2016-1867.
The crash in CVE-2016-1867 is caused by improper parsing of specially crafted JPEG 2000 image files in the jpc_pi_nextcprl() function.
Yes, CVE-2016-1867 is present in Jasper version 1.900.1 and earlier.