The jpcdecprocesssiz function in libjasper/jpc/jpcdec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.
{ "vanir_signatures": [ { "digest": { "function_hash": "94188601995937479999006365181574232397", "length": 1235.0 }, "signature_type": "Function", "source": "https://github.com/jasper-software/jasper/commit/d8c2604cd438c41ec72aff52c16ebd8183068020", "signature_version": "v1", "target": { "file": "src/libjasper/jpc/jpc_cs.c", "function": "jpc_siz_getparms" }, "deprecated": false, "id": "CVE-2016-8691-0cce8fe9" } ] }