CVE-2016-9387: Integer Overflow
An integer overflow in jpcdecprocesssiz was found that can be triggered by crafted image file when given as input to imginfo
Upstream patch:
https://github.com/mdadams/jasper/commit/d91198abd00fc435a397fe6bad906a4c1748e9cf
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
Integer overflow in the jpcdecprocesssiz function in libjasper/jpc/jpcdec.c in JasPer before 1.900.13 allows remote attackers to have unspecified impact via a crafted file, which triggers an assertion failure.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9387?
CVE-2016-9387 has a moderate severity level due to the potential for integer overflow vulnerabilities.
How do I fix CVE-2016-9387?
To remediate CVE-2016-9387, update the Jasper package to version 1.900.13 or later.
What software is affected by CVE-2016-9387?
CVE-2016-9387 affects Jasper versions up to 1.900.12.
Can CVE-2016-9387 be exploited remotely?
Yes, CVE-2016-9387 can be exploited by processing a crafted image file.
Is there a patch available for CVE-2016-9387?
Yes, an upstream patch for CVE-2016-9387 has been made available to address the vulnerability.