CVE-2016-10249 PUBLISHED

Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.

EPSS 0.54% · 67.4th percentile

Risk Scores

EPSS Score
0.54%
67.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSjasper0, 1.900.1-debian1-2.4, 1.900.1-debian1-2.4ubuntu1
Ubuntu:14.04:LTSjasper1.900.1-14ubuntu3.1, 0, 1.900.1-14ubuntu3.3

Timeline

References

Open in Interactive Console →