CVE-2016-1577

CWE-416Use After Free12 documents7 sources
Severity
7.6HIGH
EPSS
7.7%
top 8.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 14

Description

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HExploitability: 2.8 | Impact: 4.7

Affected Packages2 packages

Ubuntujasper< 1.900.1-14ubuntu3.3+1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10

🔴Vulnerability Details

4
GHSA
GHSA-w9x9-p92f-4hrr: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 12022-05-14
CVEList
CVE-2016-1577: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 12016-04-13
OSV
CVE-2016-1577: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 12016-03-03
OSV
jasper vulnerabilities2016-03-03

📋Vendor Advisories

2
Red Hat
jasper: double free issue in jas_iccattrval_destroy()2016-03-03
Ubuntu
JasPer vulnerabilities2016-03-03

💬Community

5
Bugzilla
CVE-2016-1577 jasper: Double free vulnerability in jas_iccattrval_destroy [epel-5]2016-03-03
Bugzilla
CVE-2016-1577 mingw-jasper: jasper: Double free vulnerability in jas_iccattrval_destroy [fedora-all]2016-03-03
Bugzilla
CVE-2016-1577 mingw-jasper: jasper: Double free vulnerability in jas_iccattrval_destroy [epel-7]2016-03-03
Bugzilla
CVE-2016-1577 jasper: double free issue in jas_iccattrval_destroy()2016-03-03
Bugzilla
CVE-2016-1577 jasper: Double free vulnerability in jas_iccattrval_destroy [fedora-all]2016-03-03
CVE-2016-1577 (HIGH CVSS 7.6) | Double free vulnerability in the ja | cvebase.io