PublicDateAtUSN: 2016-11-30 Candidate: CVE-2016-8654 PublicDate: 2018-08-01 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8654 https://ubuntu.com/security/notices/USN-3295-1 Description: A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected. Ubuntu-Description: Notes: mdeslaur> fixed in (1.900.1-debian1-2.4+deb8u2) Bugs: https://github.com/mdadams/jasper/issues/93 https://github.com/mdadams/jasper/issues/94 Priority: medium Discovered-by: Bingchang, Liu Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_jasper: upstream: https://github.com/mdadams/jasper/commit/4a59cfaf9ab3d48fca4a15c0d2674bf7138e3d1a upstream_jasper: needed precise_jasper: ignored (reached end-of-life) precise/esm_jasper: DNE (precise was needed) trusty_jasper: released (1.900.1-14ubuntu3.4) trusty/esm_jasper: DNE (trusty was released [1.900.1-14ubuntu3.4]) vivid/ubuntu-core_jasper: DNE vivid/stable-phone-overlay_jasper: ignored (reached end-of-life) xenial_jasper: released (1.900.1-debian1-2.4ubuntu1.1) esm-infra/xenial_jasper: released (1.900.1-debian1-2.4ubuntu1.1) yakkety_jasper: released (1.900.1-debian1-2.4+deb8u2build0.16.10.1) zesty_jasper: DNE devel_jasper: DNE