CVE-2016-9393: Medium severity Jasper Project Jasper vulnerability
Last updated 25 August 2025
Other sources
The jpcpinextrpcl function in jpct2cod.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JasPerto a version that resolves this vulnerability.Fixed in 1.900.17 - Compensating control
Mitigate the risk of remote denial of service by preventing or blocking untrusted/crafted JasPer input files from being processed until JasPer is upgraded to 1.900.17 or later.
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9393?
CVE-2016-9393 is classified as a denial of service vulnerability.
How do I fix CVE-2016-9393?
To fix CVE-2016-9393, update your Jasper software to version 1.900.17 or later.
What types of attacks can be executed using CVE-2016-9393?
CVE-2016-9393 allows remote attackers to cause denial of service through crafted files.
Which versions of Jasper are affected by CVE-2016-9393?
Jasper versions prior to 1.900.17 are affected by CVE-2016-9393.
Where can I find more information about CVE-2016-9393?
Details about CVE-2016-9393 can be found in security advisories and vulnerability databases.