Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.2.2016.739
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-739-1)
Summary:The remote host is missing an update for the Debian 'jasper' package(s) announced via the DLA-739-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'jasper' package(s) announced via the DLA-739-1 advisory.

Vulnerability Insight:
CVE-2016-8691

FPE on unknown address ... jpc_dec_process_siz ... jpc_dec.c

CVE-2016-8692

FPE on unknown address ... jpc_dec_process_siz ... jpc_dec.c

CVE-2016-8693

attempting double-free ... mem_close ... jas_stream.c

CVE-2016-8882

segfault / null pointer access in jpc_pi_destroy

CVE-2016-9560

stack-based buffer overflow in jpc_tsfb_getbands2 (jpc_tsfb.c)

CVE-2016-8887 part 1 + 2 NULL pointer dereference in jp2_colr_destroy (jp2_cod.c)

CVE-2016-8654

Heap-based buffer overflow in QMFB code in JPC codec

CVE-2016-8883

assert in jpc_dec_tiledecode()

TEMP-CVE heap-based buffer overflow in jpc_dec_tiledecode (jpc_dec.c)

For Debian 7 Wheezy, these problems have been fixed in version 1.900.1-13+deb7u5.

We recommend that you upgrade your jasper packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]

Affected Software/OS:
'jasper' package(s) on Debian 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-10249
BugTraq ID: 93838
http://www.securityfocus.com/bid/93838
Debian Security Information: DSA-3827 (Google Search)
http://www.debian.org/security/2017/dsa-3827
https://blogs.gentoo.org/ago/2016/10/23/jasper-heap-based-buffer-overflow-in-jpc_dec_tiledecode-jpc_dec-c/
RedHat Security Advisories: RHSA-2017:1208
https://access.redhat.com/errata/RHSA-2017:1208
Common Vulnerability Exposure (CVE) ID: CVE-2016-8654
BugTraq ID: 94583
http://www.securityfocus.com/bid/94583
Debian Security Information: DSA-3785 (Google Search)
https://www.debian.org/security/2017/dsa-3785
Common Vulnerability Exposure (CVE) ID: CVE-2016-8691
BugTraq ID: 93593
http://www.securityfocus.com/bid/93593
http://www.debian.org/security/2017/dsa-3785
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/THLEZURI4D24PRM7SMASC5I25IAWXXTM/
https://blogs.gentoo.org/ago/2016/10/16/jasper-two-divide-by-zero-in-jpc_dec_process_siz-jpc_dec-c/
http://www.openwall.com/lists/oss-security/2016/08/23/6
http://www.openwall.com/lists/oss-security/2016/10/16/14
Common Vulnerability Exposure (CVE) ID: CVE-2016-8692
BugTraq ID: 93588
http://www.securityfocus.com/bid/93588
Common Vulnerability Exposure (CVE) ID: CVE-2016-8693
BugTraq ID: 93587
http://www.securityfocus.com/bid/93587
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/22FCKKHQCQ3S6TZY5G44EFDTMWOJXJRD/
https://blogs.gentoo.org/ago/2016/10/16/jasper-double-free-in-mem_close-jas_stream-c/
SuSE Security Announcement: openSUSE-SU-2016:2722 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-11/msg00010.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-8882
BugTraq ID: 95864
http://www.securityfocus.com/bid/95864
http://www.openwall.com/lists/oss-security/2016/10/17/1
http://www.openwall.com/lists/oss-security/2016/10/23/8
Common Vulnerability Exposure (CVE) ID: CVE-2016-8883
BugTraq ID: 95865
http://www.securityfocus.com/bid/95865
https://usn.ubuntu.com/3693-1/
Common Vulnerability Exposure (CVE) ID: CVE-2016-8887
BugTraq ID: 93835
http://www.securityfocus.com/bid/93835
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EGI2FZQLOTSZI3VA4ECJERI74SMNQDL4/
https://blogs.gentoo.org/ago/2016/10/18/jasper-null-pointer-dereference-in-jp2_colr_destroy-jp2_cod-c
http://www.openwall.com/lists/oss-security/2016/10/23/3
http://www.openwall.com/lists/oss-security/2016/10/23/6
Common Vulnerability Exposure (CVE) ID: CVE-2016-9560
BugTraq ID: 94428
http://www.securityfocus.com/bid/94428
https://blogs.gentoo.org/ago/2016/11/20/jasper-stack-based-buffer-overflow-in-jpc_tsfb_getbands2-jpc_tsfb-c/
https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2016-9560
http://www.openwall.com/lists/oss-security/2016/11/20/1
http://www.openwall.com/lists/oss-security/2016/11/23/5
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.