Integer overflow in jbig2dec - CVE-2016-9601
Published: May 24, 2017 / Updated: May 25, 2017
Vulnerability identifier: #VU6701
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9601
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow when processing images within jbig2dec library. A remote attacker can pass a specially crafted image file to application, using the vulnerable library, and crash it.
The vulnerability exists due to integer overflow when processing images within jbig2dec library. A remote attacker can pass a specially crafted image file to application, using the vulnerable library, and crash it.
Affected software
jbig2dec
Ghostscript
Gentoo Linux
SUSE Linux
Ubuntu
Fedora
ghostscript
Ghostscript
Gentoo Linux
SUSE Linux
Ubuntu
Fedora
ghostscript
How to mitigate CVE-2016-9601
Install update from vendor's GIT repository.
ghostscript - addressed in versions 9.20-6.fc24, 9.20-6.fc25