cbcvebase.
CVE-2016-8654
published 2018-08-01

CVE-2016-8654: A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are…

high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
jasper_projectjasper< 2.0.02.0.0
jasper_projectjasper>= 0 < 1.900.1-14ubuntu3.41.900.1-14ubuntu3.4
jasper_projectjasper>= 0 < 1.900.1-debian1-2.4ubuntu1.11.900.1-debian1-2.4ubuntu1.1
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
the_jasper_projectjasper

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH