CVE-2016-9396: High severity Jasper Project Jasper vulnerability
An assertion failure was possible to trigger in JPCNOMINALGAIN.
CVE assignment:
http://seclists.org/oss-sec/2016/q4/441
Other sources
The JPCNOMINALGAIN function in jpc/jpct1cod.c in JasPer through 2.0.12 allows remote attackers to cause a denial of service (JPCCOXRFT assertion failure) via unspecified vectors.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jasperto a version that resolves this vulnerability.Fixed in 2.0.15
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9396?
CVE-2016-9396 has a medium severity rating due to an assertion failure that can be exploited by remote attackers.
How do I fix CVE-2016-9396?
To fix CVE-2016-9396, upgrade the JasPer package to version 2.0.15 or later.
Which versions of JasPer are affected by CVE-2016-9396?
Versions of JasPer prior to 2.0.15 are affected by CVE-2016-9396.
Is CVE-2016-9396 an exploitable vulnerability?
Yes, CVE-2016-9396 is considered exploitable as it allows remote attackers to trigger an assertion failure.
What component of JasPer is impacted by CVE-2016-9396?
CVE-2016-9396 impacts the JPC_NOMINALGAIN function in jasper's jpc_t1cod.c file.