CVE-2016-9398: High severity jasper reports vulnerability
Published Nov 21, 2016
·Updated
An assertion failure was possible to trigger in jpcfloorlog2.
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
The jpcfloorlog2 function in jpcmath.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
— MITRE
Affected Software
15 affected componentsFixes available
redhat/jasper<2.0.17
2.0.17
Jasper Project Jasper<1.900.17
Fedoraproject Fedora=32
Fedoraproject Fedora=33
openSUSE Leap=15.1
openSUSE Leap=15.2
openSUSE Leap=42.1
openSUSE Leap=42.2
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Desktop=12-sp2
SUSE Linux Enterprise Server=12-sp1
SUSE Linux Enterprise Server=12-sp2
SUSE Linux Enterprise Server=12-sp2
SUSE Linux Enterprise Software Development Kit=12-sp1
SUSE Linux Enterprise Software Development Kit=12-sp2
Remediation
Patch Available
Patch Available
Event History
Nov 21, 2016
Data Sourced
via Red Hat·10:21 AM
DescriptionSeverityAffected Software
Mar 23, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9398?
CVE-2016-9398 has a medium severity level due to the potential for denial of service attacks.
2
How do I fix CVE-2016-9398?
To fix CVE-2016-9398, upgrade to Jasper version 1.900.17 or later.
3
What systems are affected by CVE-2016-9398?
CVE-2016-9398 affects versions of Jasper before 1.900.17 and selected Fedora and openSUSE distributions.
4
What type of vulnerability is CVE-2016-9398 classified as?
CVE-2016-9398 is classified as an assertion failure vulnerability.
5
Can CVE-2016-9398 be exploited remotely?
Yes, CVE-2016-9398 can be exploited remotely by attackers to cause denial of service.