7.8
CVSSv3

CVE-2016-10249

Published: 15/03/2017 Updated: 05/01/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer prior to 1.900.12 allows remote malicious users to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

jasper project jasper

Vendor Advisories

Synopsis Important: jasper security update Type/Severity Security Advisory: Important Topic An update for jasper is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scor ...
Several security issues were fixed in JasPer ...
Multiple vulnerabilities have been discovered in the JasPer library for processing JPEG-2000 images, which may result in denial of service or the execution of arbitrary code if a malformed image is processed For the stable distribution (jessie), these problems have been fixed in version 19001-debian1-24+deb8u3 We recommend that you upgrade you ...
Integer overflow in the jpc_dec_tiledecode function in jpc_decc in JasPer before 190012 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow ...
A heap-based buffer overflow vulnerability has been discovered in jasper in jpc_dec_tiledecode (jpc_decc) leading to arbitrary code execution ...