CVE-2016-9389: High severity Jasper Project Jasper vulnerability
An assertion test was used when ensuring the component domains are the same for the ICT/RCT in the JPC codec.
Upstream patch:
https://github.com/mdadams/jasper/commit/dee11ec440d7908d1daf69f40a3324b27cf213ba
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
The jpcirct and jpciict functions in jpcmct.c in JasPer before 1.900.14 allow remote attackers to cause a denial of service (assertion failure).
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jasperto a version that resolves this vulnerability.Fixed in 1.900.14 - Upgrade
Upgrade
jasperto a version that resolves this vulnerability.Fixed in 1.900.14
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9389?
CVE-2016-9389 is classified as a medium severity vulnerability.
How do I fix CVE-2016-9389?
To resolve CVE-2016-9389, update the Jasper package to version 1.900.14 or later.
What software is affected by CVE-2016-9389?
CVE-2016-9389 affects the Jasper codec in versions up to 1.900.13.
What is the nature of CVE-2016-9389?
CVE-2016-9389 is an assertion test vulnerability in the JPC codec related to component domain validation.
Is there a known patch for CVE-2016-9389?
Yes, there is an upstream patch available for CVE-2016-9389 that addresses the vulnerability.