CVE-2016-9583: Integer Overflow
An out-of-bounds heap read vulnerability was found in jpcpinextpcrl() function of jasper when processing crafted input.
Upstream bug:
https://github.com/mdadams/jasper/issues/103
Upstream patch:
https://github.com/mdadams/jasper/commit/99a50593254d1b53002719bbecfc946c84b23d27
Acknowledgments:
Name: Liu Bingchang (IIE)
Other sources
An out-of-bounds heap read vulnerability was found in the jpcpinextpcrl() function of jasper before 2.0.6 when processing crafted input.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9583?
CVE-2016-9583 is classified as a medium severity vulnerability due to its potential for exploitation through crafted input.
How do I fix CVE-2016-9583?
To fix CVE-2016-9583, update the jasper package to version 2.0.6 or later.
Which versions of Red Hat products are affected by CVE-2016-9583?
CVE-2016-9583 affects Red Hat Enterprise Linux Desktop 6.0 and 7.0, Red Hat Enterprise Linux Server 6.0 and 7.0, and their respective variants.
What type of vulnerability is CVE-2016-9583?
CVE-2016-9583 is an out-of-bounds heap read vulnerability found in the jpc_pi_nextpcrl() function of the jasper library.
How can I check if my system is vulnerable to CVE-2016-9583?
You can check if your system is vulnerable to CVE-2016-9583 by verifying the version of the jasper package installed and comparing it to the affected versions.