CVE-2016-2089: Input Validation
A vulnerability was found in the way the JasPer's jasmatrixclip() function parses certain JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.
Original bug report (with reproducer attached):
http://seclists.org/oss-sec/2016/q1/233
CVE assignment:
http://seclists.org/oss-sec/2016/q1/235
Other sources
The jasmatrixclip function in jasseq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2089?
CVE-2016-2089 has a severity rating that indicates it can lead to denial of service due to application crashes.
How do I fix CVE-2016-2089?
To fix CVE-2016-2089, upgrade the JasPer library to version 1.900.3 or later.
What is the impact of CVE-2016-2089?
The impact of CVE-2016-2089 is that it allows attackers to cause crashes through specially crafted JPEG 2000 images.
Which versions of JasPer are affected by CVE-2016-2089?
JasPer version 1.900.1 is specifically affected by CVE-2016-2089.
Who reported CVE-2016-2089?
CVE-2016-2089 was reported as a vulnerability related to the processing of JPEG 2000 images in JasPer.