First published: Thu Dec 15 2016(Updated: )
An out-of-bounds heap read vulnerability was found in jpc_pi_nextpcrl() function of jasper when processing crafted input. Upstream bug: <a href="https://github.com/mdadams/jasper/issues/103">https://github.com/mdadams/jasper/issues/103</a> Upstream patch: <a href="https://github.com/mdadams/jasper/commit/99a50593254d1b53002719bbecfc946c84b23d27">https://github.com/mdadams/jasper/commit/99a50593254d1b53002719bbecfc946c84b23d27</a> Acknowledgments: Name: Liu Bingchang (IIE)
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jasper | <2.0.6 | 2.0.6 |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.3 | |
redhat enterprise Linux server aus | =7.4 | |
redhat enterprise Linux server aus | =7.6 | |
redhat enterprise Linux server eus | =7.3 | |
redhat enterprise Linux server eus | =7.4 | |
redhat enterprise Linux server eus | =7.5 | |
redhat enterprise Linux server eus | =7.6 | |
redhat enterprise Linux server tus | =7.3 | |
redhat enterprise Linux server tus | =7.6 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
Jasper Reports | <2.0.6 | |
Oracle Outside In Technology | =8.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9583 is classified as a medium severity vulnerability due to its potential for exploitation through crafted input.
To fix CVE-2016-9583, update the jasper package to version 2.0.6 or later.
CVE-2016-9583 affects Red Hat Enterprise Linux Desktop 6.0 and 7.0, Red Hat Enterprise Linux Server 6.0 and 7.0, and their respective variants.
CVE-2016-9583 is an out-of-bounds heap read vulnerability found in the jpc_pi_nextpcrl() function of the jasper library.
You can check if your system is vulnerable to CVE-2016-9583 by verifying the version of the jasper package installed and comparing it to the affected versions.