CVE-2016-1577
Severity
7.6HIGH
EPSS
7.7%
top 8.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateMay 14
Description
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HExploitability: 2.8 | Impact: 4.7
Affected Packages2 packages
Also affects: Ubuntu Linux 12.04, 14.04, 15.10
🔴Vulnerability Details
4GHSA▶
GHSA-w9x9-p92f-4hrr: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1↗2022-05-14
CVEList▶
CVE-2016-1577: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1↗2016-04-13
OSV▶
CVE-2016-1577: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1↗2016-03-03