JasPer jpc_pi_nextcprolactin Denial of Service Vulnerability (CVE-2016-1867)
JasPer jpc_pi_nextcprolactin Denial of Service Vulnerability (CVE-2016-1867)
Release date:
Updated on:
Affected Systems:
University of Victoria JasPer 1.900.1
Description:
CVE (CAN) ID: CVE-2016-1867
JasPer includes a reference software implementation that provides the JPEG-2000 Part-1 standard definition of the decoder, written in C language.
The jpc_pi_nextcprolactin function in JasPer 1.900.1 has a security vulnerability. Remote attackers can exploit this vulnerability to cause DoS (out-of-bounds read and application crash) by constructing JPEG 2000 images ).
<* Source: vendor
*>
Suggestion:
Vendor patch:
University of Victoria
----------------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.ece.uvic.ca /~ Frodo/jasper/# download
This article permanently updates the link address: