CVE-2016-9262: Integer Overflow
A number of overflows were found in jasper causing use after free vulnerability triggeerd by creafted image.
Upstream patch:
https://github.com/mdadams/jasper/commit/634ce8e8a5accc0fa05dd2c20d42b4749d4b2735
Reproducer:
https://github.com/asarubbo/poc/blob/master/00028-jasper-uaf-jasrealloc
CVE assignment:
http://seclists.org/oss-sec/2016/q4/385
Other sources
Multiple integer overflows in the (1) jasrealloc function in base/jasmalloc.c and (2) memresize function in base/jasstream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9262?
CVE-2016-9262 is classified as a moderate severity vulnerability due to the potential for use after free exploitation.
How do I fix CVE-2016-9262?
To fix CVE-2016-9262, users should upgrade to jasper version 1.900.22 or later on Red Hat systems.
What types of software are affected by CVE-2016-9262?
CVE-2016-9262 affects the jasper image processing software across various distributions including Debian and Red Hat.
What are the potential consequences of CVE-2016-9262 exploitation?
Exploitation of CVE-2016-9262 could lead to arbitrary code execution and system compromise through crafted images.
Is there a patch available for CVE-2016-9262?
Yes, a patch for CVE-2016-9262 is included in jasper version 1.900.22 and later.