First published: Mon Nov 21 2016(Updated: )
An assertion failure was possible to trigger in JPC_NOMINALGAIN. CVE assignment: <a href="http://seclists.org/oss-sec/2016/q4/441">http://seclists.org/oss-sec/2016/q4/441</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/jasper | ||
redhat/jasper | <2.0.15 | 2.0.15 |
Jasper Reports | <=1.900.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9396 has a medium severity rating due to an assertion failure that can be exploited by remote attackers.
To fix CVE-2016-9396, upgrade the JasPer package to version 2.0.15 or later.
Versions of JasPer prior to 2.0.15 are affected by CVE-2016-9396.
Yes, CVE-2016-9396 is considered exploitable as it allows remote attackers to trigger an assertion failure.
CVE-2016-9396 impacts the JPC_NOMINALGAIN function in jasper's jpc_t1cod.c file.