NULL pointer dereference in jbig2dec - CVE-2017-9216

 

NULL pointer dereference in jbig2dec - CVE-2017-9216

Published: May 14, 2018


Vulnerability identifier: #VU12612
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9216
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the jbig2_huffman_get function in jbig2_huffman.c due to NULL pointer dereference. A remote attacker can cause the service to crash when parsing an invalid file.

Affected software

jbig2dec
Arch Linux
Ubuntu
Fedora
libjbig2dec0 (Ubuntu package)
jbig2dec (Ubuntu package)
jbig2dec

How to mitigate CVE-2017-9216

Install update from vendor's website.

libjbig2dec0 (Ubuntu package) - update to 0.12+201509181ubuntu0.1+esm2
jbig2dec (Ubuntu package) - update to 0.12+201509181ubuntu0.1+esm2
jbig2dec - addressed in versions 0.14-1.fc25, 0.14-1.fc26, 0.14-1.fc27

External References

Related Security Bulletins