CVE-2016-8691: Divide by Zero
Divide by zero vulnerability was found in jpcdecprocesssiz triggered by invoking imginfo command on specially crafted file.
Upstream patch:
https://github.com/mdadams/jasper/commit/d8c2604cd438c41ec72aff52c16ebd8183068020
CVE assignment:
http://www.openwall.com/lists/oss-security/2016/10/16/14
Other sources
The jpcdecprocesssiz function in libjasper/jpc/jpcdec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8691?
CVE-2016-8691 is classified as a medium severity vulnerability due to its potential impact on system stability.
How does CVE-2016-8691 exploit the divide by zero vulnerability?
CVE-2016-8691 exploits a divide by zero vulnerability in the jpc_dec_process_siz function which can be triggered by processing a specially crafted file.
What versions of Jasper are affected by CVE-2016-8691?
CVE-2016-8691 affects Jasper versions up to and including 1.900.3.
How do I fix CVE-2016-8691?
To fix CVE-2016-8691, upgrade Jasper to version 1.900.4 or later.
Which operating systems are impacted by CVE-2016-8691?
CVE-2016-8691 impacts Debian 8.0 and Fedora 25 among other platforms that use affected versions of Jasper.