CVE-2016-9392: Medium severity Jasper Project Jasper vulnerability
Last updated 25 August 2025
Other sources
The calcstepsizes function in jpcdec.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
— Launchpad
There were missing sanity checks in jpcsizgetparms.
Upstream patch:
https://github.com/mdadams/jasper/commit/f7038068550fba0e41e1d0c355787f1dcd5bf330
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jasperto a version that resolves this vulnerability.Fixed in 1.900.17 - Upgrade
Upgrade
jasperto a version that resolves this vulnerability.Fixed in 1.900.17Patch f7038068550fba0e41e1d0c355787f1dcd5bf330
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9392?
CVE-2016-9392 has a severity rating that indicates it could lead to denial of service due to assertion failure.
How do I fix CVE-2016-9392?
To mitigate CVE-2016-9392, upgrade to jasper version 1.900.17 or later.
What software is affected by CVE-2016-9392?
CVE-2016-9392 affects jasper versions prior to 1.900.17.
What kind of attacks can exploit CVE-2016-9392?
CVE-2016-9392 can be exploited by remote attackers using crafted files, leading to denial of service.
Where can I find more information on CVE-2016-9392?
Details about CVE-2016-9392 can typically be found in security advisories from affected software vendors.