CVE-2016-9394: Input Validation
Last updated 25 August 2025
Other sources
The jasseq2dcreate function in jasseq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JasPerto a version that resolves this vulnerability.Fixed in 1.900.17
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9394?
CVE-2016-9394 has a severity rating that classifies it as a denial of service vulnerability.
How do I fix CVE-2016-9394?
To fix CVE-2016-9394, upgrade to JasPer version 1.900.17 or later.
What software is affected by CVE-2016-9394?
CVE-2016-9394 affects JasPer versions prior to 1.900.17.
What impact does CVE-2016-9394 have on systems?
CVE-2016-9394 can lead to a denial of service by causing an assertion failure when processing crafted files.
Who can exploit CVE-2016-9394?
Remote attackers can exploit CVE-2016-9394 by sending specifically crafted files to vulnerable systems.