Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mdadams

#19657of 53,624
13.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-10104
7.8
2016-12-21
Jasper · Jasper · CVE-2016-9387
**Name of the Vulnerable Software and Affected Versions** JasPer versions prior to 1.900.13 **Description** The issue is related to an integer overflow in the `jpc dec process siz` function, which can be triggered by a crafted file. This leads to an assertion failure. **Recommendations** For versions prior to 1.900.13, update to version 1.900.13 or later to resolve the issue.
PT-2017-9855
5.5
2016-11-10
Jasper · Jasper · CVE-2016-8884
**Name of the Vulnerable Software and Affected Versions** JasPer version 1.900.5 **Description** The issue allows remote attackers to cause a denial of service by calling the imginfo command with a crafted BMP image, resulting in a NULL pointer dereference. This is due to an incomplete fix for a previous issue. **Recommendations** For JasPer version 1.900.5, consider avoiding the use of the `bmp getdata` function in libjasper/bmp/bmp dec.c until a complete fix is available. As a temporary workaround, restrict the processing of crafted BMP images to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.