CVE-2016-9388: Medium severity jasper reports vulnerability
Improper error handling in RAS encoder/decoder with assertion test were found.
Upstream patch:
https://github.com/mdadams/jasper/commit/411a4068f8c464e883358bf403a3e25158863823
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
The rasgetcmap function in rasdec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9388?
CVE-2016-9388 has been classified with a medium severity level due to improper error handling.
How do I fix CVE-2016-9388?
To fix CVE-2016-9388, ensure that you update the Jasper package to version 1.900.14 or later.
Which software is affected by CVE-2016-9388?
CVE-2016-9388 affects the Jasper package, specifically versions below 1.900.14.
What kind of vulnerability is CVE-2016-9388?
CVE-2016-9388 is an improper error handling vulnerability found in the RAS encoder/decoder.
Is there an upstream patch for CVE-2016-9388?
Yes, an upstream patch for CVE-2016-9388 has been released, addressing the assertion test issue.