CVE-2016-8884: Null Pointer Dereference
Published Mar 28, 2017
·Updated
The bmpgetdata function in libjasper/bmp/bmpdec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8690.
Affected Software
3 affected components
Jasper Project Jasper=1.900.5
Fedoraproject Fedora=23
Fedoraproject Fedora=24
Remediation
Patch Available
Event History
Mar 28, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-8884?
CVE-2016-8884 is considered a denial of service vulnerability due to a NULL pointer dereference.
2
How do I fix CVE-2016-8884?
To fix CVE-2016-8884, update to a patched version of JasPer that addresses the issue.
3
What effect does CVE-2016-8884 have on affected systems?
CVE-2016-8884 allows remote attackers to crash systems through specially crafted BMP images.
4
Which software versions are affected by CVE-2016-8884?
The affected software versions include JasPer 1.900.5 and Fedora versions 23 and 24.
5
Can CVE-2016-8884 be exploited remotely?
Yes, CVE-2016-8884 can be exploited remotely by sending crafted BMP images to the affected applications.