First published: Thu Jan 28 2016(Updated: )
The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jasper | <1.900.3 | 1.900.3 |
Jasper Reports | =1.900.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2089 has a severity rating that indicates it can lead to denial of service due to application crashes.
To fix CVE-2016-2089, upgrade the JasPer library to version 1.900.3 or later.
The impact of CVE-2016-2089 is that it allows attackers to cause crashes through specially crafted JPEG 2000 images.
JasPer version 1.900.1 is specifically affected by CVE-2016-2089.
CVE-2016-2089 was reported as a vulnerability related to the processing of JPEG 2000 images in JasPer.