CVE-2016-8693: Double Free
A double free vulnerability was found in memclose in jasstream.c triggered by invoking imginfo command on specially crafted image file.
CVE assignment:
http://www.openwall.com/lists/oss-security/2016/10/16/14
Other sources
Double free vulnerability in the memclose function in jasstream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8693?
CVE-2016-8693 is classified as a moderate severity vulnerability due to its potential impact on application stability.
How do I fix CVE-2016-8693?
To fix CVE-2016-8693, upgrade affected versions of the jasper package to at least version 1.900.10 or apply relevant patches.
What software is affected by CVE-2016-8693?
CVE-2016-8693 affects the jasper package versions prior to 1.900.10, and specific distributions including Debian, Fedora, and openSUSE.
What type of vulnerability is CVE-2016-8693?
CVE-2016-8693 is a double free vulnerability that occurs in the mem_close function within jas_stream.c.
How can CVE-2016-8693 be exploited?
CVE-2016-8693 can be exploited by an attacker who triggers the vulnerability through specially crafted image files.