Reachable Assertion in JasPer - CVE-2016-9396
Published: November 2, 2018
Vulnerability identifier: #VU15698
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9396
CWE-ID: CWE-617
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attacks.
The vulnerability exists due to reachable assertion in JPC_NOMINALGAIN function in jpc/jpc_t1cod.c in JasPer through 2.0.12. A remote attacker can perform a denial of service (DoS) attack via unspecified vectors.
Affected software
JasPer
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
How to mitigate CVE-2016-9396
Install update from vendor's website.
JasPer - update to 2.0.14
External References
- http://www.openwall.com/lists/oss-security/2016/11/17/1
- https://access.redhat.com/errata/RHSA-2018:3253
- https://blogs.gentoo.org/ago/2016/11/16/jasper-multiple-assertion-failure
- https://bugzilla.redhat.com/show_bug.cgi?id=1396978
- https://bugzilla.redhat.com/show_bug.cgi?id=1485272
- https://usn.ubuntu.com/3693-1/
- https://github.com/mdadams/jasper/issues/50