PT-2016-4869 · Jasper+5 · Jasper+5
Baines-Jacob
+1
·
Published
2016-03-03
·
Updated
2024-06-15
·
CVE-2016-1577
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
JasPer versions 1.900.1 and earlier
Description
A double free vulnerability in the
jas iccattrval destroy function allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.Recommendations
For JasPer versions 1.900.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Jasper
Red Hat
Suse
Ubuntu