CVE-2016-9397: High severity jasper reports vulnerability
Published Nov 21, 2016
·Updated
An assertion failure was possible to trigger in jpcdequantize.
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
The jpcdequantize function in jpcdec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
— MITRE
Affected Software
3 affected components
Jasper Project Jasper=1.900.13
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Remediation
Patch Available
Event History
Nov 21, 2016
Data Sourced
10:20 AM
DescriptionSeverityAffected Software
Mar 23, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9397?
CVE-2016-9397 has been identified as a denial of service vulnerability.
2
How do I fix CVE-2016-9397?
To fix CVE-2016-9397, update the Jasper software to the latest version available.
3
Which versions are affected by CVE-2016-9397?
CVE-2016-9397 affects Jasper 1.900.13 and specific versions of Fedora, including 32 and 33.
4
Can CVE-2016-9397 be exploited remotely?
Yes, CVE-2016-9397 can be exploited by remote attackers to trigger an assertion failure.
5
What component of the software is impacted by CVE-2016-9397?
CVE-2016-9397 impacts the jpc_dequantize function in jpc_dec.c within Jasper software.