JasPer CVE-2016-9591 Denial of Service Vulnerability

JasPer is prone to a denial-of-service vulnerability.

Attackers can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.

JasPer 2.0.8 is vulnerable; prior versions may also be affected.


Bugtraq ID: 94952
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2016-9591

Remote: Yes
Local: No
Published: Dec 16 2016 12:00AM
Updated: Apr 14 2017 12:04AM
Credit: twelveand0
Vulnerable: jasper_project jasper 2.0.8
Debian Linux 6.0 sparc
Debian Linux 6.0 s/390
Debian Linux 6.0 powerpc
Debian Linux 6.0 mips
Debian Linux 6.0 ia-64
Debian Linux 6.0 ia-32
Debian Linux 6.0 arm
Debian Linux 6.0 amd64

Not Vulnerable:


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.

Related Posts