Related Vulnerabilities: CVE-2016-9560  

A stack buffer overflow vulnerability has been discovered in jpc/jpc_dec.c duo to an out of bounds array write triggered by a crafted image.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

A  stack buffer overflow vulnerability has been discovered in jpc/jpc_dec.c duo to an out of bounds array write triggered by a crafted image.

AVG-14 jasper 1.900.1-15 1.900.31-1 Critical Fixed

07 Dec 2016 ASA-201612-9 AVG-14 jasper Critical multiple issues

https://github.com/mdadams/jasper/commit/1abc2e5a401a4bf1d5ca4df91358ce5df111f495
http://www.openwall.com/lists/oss-security/2016/11/23/5