CVE-2016-9395: Input Validation
An assertion failure was possible to trigger in jasseq2dcreate.
Upstream patch:
https://github.com/mdadams/jasper/commit/d42b2388f7f8e0332c846675133acea151fc557a
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
The jasseq2dcreate function in jasseq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9395?
CVE-2016-9395 is classified as having a medium severity level due to the potential for an assertion failure.
How do I fix CVE-2016-9395?
To resolve CVE-2016-9395, upgrade to Jasper version 1.900.25 or later.
What software is affected by CVE-2016-9395?
CVE-2016-9395 affects Jasper versions up to 1.900.24 and can be exploited in both the Jasper package from Red Hat and other installations.
What type of vulnerability is CVE-2016-9395?
CVE-2016-9395 is an assertion failure vulnerability that can be triggered in the jas_seq2d_create function.
How can I check if my system is vulnerable to CVE-2016-9395?
You can check your Jasper software version and verify if it is earlier than 1.900.25 to determine vulnerability to CVE-2016-9395.