CVE-2016-9560
high
CVSS v3
7.8
CVSS v4 NEW
โ
VIR risk
7.8
Description
Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image.
Predictions
Exploit likelihood
75%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 1.900.31-1 | |
| sles | affected | | |
| debian | 8.0 | affected | |
| rhel | 6.0 | affected | |
| rhel | 7.0 | affected | |
| rhel | 7.3 | affected | |
| rhel | 7.4 | affected | |
| rhel | 7.5 | affected | |
| rhel | 7.6 | affected | |
| rhel | 7.7 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| jasper_project | jasper | {"endExcluding":"1.900.30"} | 1.900.30 |
References
- https://security.archlinux.org/ASA-201612-9
- http://www.debian.org/security/2017/dsa-3785
- http://www.openwall.com/lists/oss-security/2016/11/20/1
- http://www.openwall.com/lists/oss-security/2016/11/23/5
- http://www.securityfocus.com/bid/94428
- https://access.redhat.com/errata/RHSA-2017:1208
- https://blogs.gentoo.org/ago/2016/11/20/jasper-stack-based-buffer-overflow-in-jpc_tsfb_getbands2-jpc_tsfb-c/
- https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2016-9560
- https://github.com/mdadams/jasper/commit/1abc2e5a401a4bf1d5ca4df91358ce5df111f495
- https://www.suse.com/security/cve/CVE-2016-9560.html
CWEs
CWE-787
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.