Vulnerability Description
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jasper Project | Jasper | < 2.0.0 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
| Redhat | Enterprise Linux Server Eus | 7.3 |
| Redhat | Enterprise Linux Workstation | 6.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94583Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1208Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8654ExploitIssue TrackingPatch
- https://github.com/mdadams/jasper/commit/4a59cfaf9ab3d48fca4a15c0d2674bf7138e3d1PatchThird Party Advisory
- https://github.com/mdadams/jasper/issues/93ExploitThird Party Advisory
- https://github.com/mdadams/jasper/issues/94ExploitThird Party Advisory
- https://www.debian.org/security/2017/dsa-3785Third Party Advisory
- http://www.securityfocus.com/bid/94583Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1208Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8654ExploitIssue TrackingPatch
- https://github.com/mdadams/jasper/commit/4a59cfaf9ab3d48fca4a15c0d2674bf7138e3d1PatchThird Party Advisory
- https://github.com/mdadams/jasper/issues/93ExploitThird Party Advisory
- https://github.com/mdadams/jasper/issues/94ExploitThird Party Advisory
- https://www.debian.org/security/2017/dsa-3785Third Party Advisory
FAQ
What is CVE-2016-8654?
CVE-2016-8654 is a vulnerability with a CVSS score of 7.8 (HIGH). A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
How severe is CVE-2016-8654?
CVE-2016-8654 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8654?
Check the references section above for vendor advisories and patch information. Affected products include: Jasper Project Jasper, Debian Debian Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Aus.