PublicDateAtUSN: 2016-12-16 Candidate: CVE-2016-9591 PublicDate: 2018-03-09 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9591 http://www.openwall.com/lists/oss-security/2016/12/16/3 https://ubuntu.com/security/notices/USN-3295-1 Description: JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer. Ubuntu-Description: Notes: mdeslaur> fixed in (1.900.1-debian1-2.4+deb8u3) Bugs: https://github.com/mdadams/jasper/issues/105 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_jasper: upstream: https://github.com/mdadams/jasper/commit/03fe49ab96bf65fea784cdc256507ea88267fc7c upstream_jasper: released (1.900.1-debian1-2.4+deb8u3) precise_jasper: ignored (reached end-of-life) precise/esm_jasper: DNE (precise was needed) trusty_jasper: released (1.900.1-14ubuntu3.4) trusty/esm_jasper: DNE (trusty was released [1.900.1-14ubuntu3.4]) vivid/ubuntu-core_jasper: DNE vivid/stable-phone-overlay_jasper: ignored (reached end-of-life) xenial_jasper: released (1.900.1-debian1-2.4ubuntu1.1) esm-infra/xenial_jasper: released (1.900.1-debian1-2.4ubuntu1.1) yakkety_jasper: released (1.900.1-debian1-2.4+deb8u3build0.16.10.1) zesty_jasper: DNE devel_jasper: DNE