First published: Mon Nov 21 2016(Updated: )
An assertion failure was possible to trigger in jpc_dequantize. CVE assignment: <a href="http://seclists.org/oss-sec/2016/q4/441">http://seclists.org/oss-sec/2016/q4/441</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jasper Reports | =1.900.13 | |
Red Hat Fedora | =32 | |
Red Hat Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9397 has been identified as a denial of service vulnerability.
To fix CVE-2016-9397, update the Jasper software to the latest version available.
CVE-2016-9397 affects Jasper 1.900.13 and specific versions of Fedora, including 32 and 33.
Yes, CVE-2016-9397 can be exploited by remote attackers to trigger an assertion failure.
CVE-2016-9397 impacts the jpc_dequantize function in jpc_dec.c within Jasper software.