Candidate: CVE-2016-9398 PublicDate: 2017-03-23 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9398 http://www.openwall.com/lists/oss-security/2016/11/17/1 https://github.com/asarubbo/poc/blob/master/00023-jasper-assert-jpc_floorlog2 (testcase) Description: The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors. Ubuntu-Description: Notes: Bugs: https://github.com/mdadams/jasper/issues/71 Priority: negligible Discovered-by: Agostino Sarubbo Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_jasper: other: https://github.com/jasper-maint/jasper/pull/38 upstream_jasper: needs-triage precise_jasper: ignored (reached end-of-life) precise/esm_jasper: DNE (precise was needs-triage) trusty_jasper: ignored (reached end-of-life) trusty/esm_jasper: DNE (trusty was deferred [2020-07-22]) vivid/ubuntu-core_jasper: DNE vivid/stable-phone-overlay_jasper: ignored (reached end-of-life) xenial_jasper: ignored (end of standard support, was needed) esm-infra/xenial_jasper: needed yakkety_jasper: ignored (reached end-of-life) zesty_jasper: DNE artful_jasper: DNE bionic_jasper: DNE cosmic_jasper: DNE disco_jasper: DNE eoan_jasper: DNE focal_jasper: DNE groovy_jasper: DNE hirsute_jasper: DNE impish_jasper: DNE jammy_jasper: DNE devel_jasper: DNE