NULL pointer dereference in jbig2dec - CVE-2017-9216
Published: May 14, 2018
Vulnerability identifier: #VU12612
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9216
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the jbig2_huffman_get function in jbig2_huffman.c due to NULL pointer dereference. A remote attacker can cause the service to crash when parsing an invalid file.
The weakness exists in the jbig2_huffman_get function in jbig2_huffman.c due to NULL pointer dereference. A remote attacker can cause the service to crash when parsing an invalid file.
Affected software
jbig2dec
Arch Linux
Ubuntu
Fedora
libjbig2dec0 (Ubuntu package)
jbig2dec (Ubuntu package)
jbig2dec
Arch Linux
Ubuntu
Fedora
libjbig2dec0 (Ubuntu package)
jbig2dec (Ubuntu package)
jbig2dec
How to mitigate CVE-2017-9216
Install update from vendor's website.
libjbig2dec0 (Ubuntu package) - update to 0.12+201509181ubuntu0.1+esm2
jbig2dec (Ubuntu package) - update to 0.12+201509181ubuntu0.1+esm2
jbig2dec - addressed in versions 0.14-1.fc25, 0.14-1.fc26, 0.14-1.fc27
jbig2dec (Ubuntu package) - update to 0.12+201509181ubuntu0.1+esm2
jbig2dec - addressed in versions 0.14-1.fc25, 0.14-1.fc26, 0.14-1.fc27