Unrated severityNVD Advisory· Published Aug 1, 2018· Updated Aug 6, 2024
CVE-2016-8654
CVE-2016-8654
Description
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
Affected products
14- osv-coords13 versionspkg:rpm/opensuse/jasper&distro=openSUSE%20Tumbleweedpkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/jasper&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2
< 1.900.14-3.1+ 12 more
- (no CPE)range: < 1.900.14-3.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-134.32.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-134.32.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-134.32.1
- (no CPE)range: < 1.900.14-184.1
- (no CPE)range: < 1.900.14-184.1
- The Jasper Project/jasperv5Range: 2.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- access.redhat.com/errata/RHSA-2017:1208mitrevendor-advisoryx_refsource_REDHAT
- www.debian.org/security/2017/dsa-3785mitrevendor-advisoryx_refsource_DEBIAN
- www.securityfocus.com/bid/94583mitrevdb-entryx_refsource_BID
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- github.com/mdadams/jasper/commit/4a59cfaf9ab3d48fca4a15c0d2674bf7138e3d1amitrex_refsource_CONFIRM
- github.com/mdadams/jasper/issues/93mitrex_refsource_CONFIRM
- github.com/mdadams/jasper/issues/94mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.