CVE-2016-9390: Input Validation
An assertion failure was found in jasper triggered when tiles lie outside of the image area.
Upstream patch:
https://github.com/mdadams/jasper/commit/ba2b9d000660313af7b692542afbd374c5685865
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
The jasseq2dcreate function in jasseq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jasperto a version that resolves this vulnerability.Fixed in 1.900.14 - Upgrade
Upgrade
jasperto a version that resolves this vulnerability.Fixed in 1.900.14
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9390?
CVE-2016-9390 is considered a moderate severity vulnerability due to potential impact on application stability.
How do I fix CVE-2016-9390?
To fix CVE-2016-9390, update the jasper package to version 1.900.14 or higher.
What does CVE-2016-9390 affect?
CVE-2016-9390 affects the jasper image processing library, particularly versions up to 1.900.13.
What type of vulnerability is CVE-2016-9390?
CVE-2016-9390 involves an assertion failure triggered by tiles lying outside the image area.
Is CVE-2016-9390 exploitable?
While CVE-2016-9390 may not lead to remote code execution, it can cause application crashes, making it exploitable in certain contexts.