PublicDateAtUSN: 2016-03-03 14:00:00 UTC Candidate: CVE-2016-1577 CRD: 2016-03-03 14:00:00 UTC PublicDate: 2016-04-13 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1577 https://ubuntu.com/security/notices/USN-2919-1 Description: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137. Ubuntu-Description: Notes: Bugs: https://launchpad.net/bugs/1547865 Priority: medium Discovered-by: Jacob Baines Assigned-to: tyhicks CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H [7.6 HIGH] Patches_jasper: upstream: https://github.com/mdadams/jasper/commit/74ea22a7a4fe186e0a0124df25e19739b77c4a29 upstream_jasper: needed precise_jasper: released (1.900.1-13ubuntu0.3) precise/esm_jasper: DNE (precise was released [1.900.1-13ubuntu0.3]) trusty_jasper: released (1.900.1-14ubuntu3.3) trusty/esm_jasper: DNE (trusty was released [1.900.1-14ubuntu3.3]) vivid/ubuntu-core_jasper: DNE vivid/stable-phone-overlay_jasper: ignored (reached end-of-life) wily_jasper: released (1.900.1-debian1-2.4ubuntu0.15.10.1) xenial_jasper: released (1.900.1-debian1-2.4ubuntu1) esm-infra/xenial_jasper: released (1.900.1-debian1-2.4ubuntu1) yakkety_jasper: released (1.900.1-debian1-2.4ubuntu1) zesty_jasper: DNE devel_jasper: DNE