First published: Mon Oct 17 2016(Updated: )
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jasper | <1.900.9 | 1.900.9 |
Jasper Reports | <=1.900.29 | |
Fedora | =23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8690 is classified as a denial of service vulnerability due to a NULL pointer dereference.
To fix CVE-2016-8690, upgrade to Jasper version 1.900.9 or later.
CVE-2016-8690 affects versions of JasPer prior to 1.900.5 and specific distributions like Fedora 23.
Yes, CVE-2016-8690 can be exploited remotely via crafted BMP images in the imginfo command.
If upgrading is not possible, consider implementing additional security measures such as input validation to mitigate the impact of CVE-2016-8690.