Candidate: CVE-2016-9399 PublicDate: 2017-03-23 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9399 https://github.com/asarubbo/poc/blob/master/00044-jasper-assert-calcstepsizes (testcase) http://www.openwall.com/lists/oss-security/2016/11/17/1 Description: The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors. Ubuntu-Description: Notes: Bugs: https://github.com/mdadams/jasper/issues/83 Priority: negligible Discovered-by: Agostino Sarubbo Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_jasper: upstream: https://github.com/jasper-software/jasper/commit/84d00fb29a22e360c2ff91bdc2cd81c288826bfc upstream_jasper: needs-triage precise_jasper: ignored (reached end-of-life) precise/esm_jasper: DNE (precise was needs-triage) trusty_jasper: ignored (reached end-of-life) trusty/esm_jasper: DNE (trusty was deferred [2020-07-22]) vivid/ubuntu-core_jasper: DNE vivid/stable-phone-overlay_jasper: ignored (reached end-of-life) xenial_jasper: ignored (end of standard support, was needed) esm-infra/xenial_jasper: needed yakkety_jasper: ignored (reached end-of-life) zesty_jasper: DNE artful_jasper: DNE bionic_jasper: DNE cosmic_jasper: DNE disco_jasper: DNE eoan_jasper: DNE focal_jasper: DNE groovy_jasper: DNE hirsute_jasper: DNE impish_jasper: DNE jammy_jasper: DNE devel_jasper: DNE