First published: Mon Nov 21 2016(Updated: )
An assertion failure was possible to trigger in calcstepsizes. CVE assignment: <a href="http://seclists.org/oss-sec/2016/q4/441">http://seclists.org/oss-sec/2016/q4/441</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jasper | <2.0.17 | 2.0.17 |
Jasper Reports | =1.900.22 | |
Fedora | =32 | |
Fedora | =33 | |
openSUSE | =15.1 | |
openSUSE | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9399 is classified as a denial of service vulnerability.
To remediate CVE-2016-9399, upgrade the Jasper library to version 2.0.17 or later.
CVE-2016-9399 affects versions 1.900.22 of the Jasper Project as well as specific versions in Fedora and openSUSE.
CVE-2016-9399 is an assertion failure vulnerability that can be triggered in the calcstepsizes function.
Yes, CVE-2016-9399 can be exploited remotely, leading to a denial of service.