PT-2017-3785 · Jasper+5 · Jasper+5

Owl337

·

Publicado

2016-12-21

·

Atualizado

2024-06-15

·

CVE-2016-9396

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions JasPer versions through 2.0.12
Description The issue is related to errors in processing JPEG-2000 images, specifically in the JPC NOMINALGAIN function. It allows remote attackers to cause a denial of service via unspecified vectors, potentially by using a specially crafted image.
Recommendations For versions through 2.0.12, consider updating to a version that fixes the JPC NOMINALGAIN function issue to prevent denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Assertion Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2474
BDU:2019-02458
CESA-2018_3253
CVE-2016-9396
MGASA-2017-0474
MGASA-2018-0281
OPENSUSE-SU-2019:1315-1
OPENSUSE-SU-2019_1315-1
OPENSUSE-SU-2024:10869-1
RHSA-2018:3253
RHSA-2018_3253
SUSE-SU-2019:1018-1
SUSE-SU-2019:2513-1
SUSE-SU-2019_1018-1
SUSE-SU-2019_2513-1
USN-3693-1

Produtos afetados

Alt Linux
Centos
Jasper
Red Hat
Suse
Ubuntu