Integer overflow in the jpcdecprocesssiz function in libjasper/jpc/jpcdec.c in JasPer before 1.900.13 allows remote attackers to have unspecified impact via a crafted file, which triggers an assertion failure.
{ "vanir_signatures": [ { "source": "https://github.com/jasper-software/jasper/commit/d91198abd00fc435a397fe6bad906a4c1748e9cf", "signature_type": "Line", "target": { "file": "src/libjasper/jpc/jpc_dec.c" }, "id": "CVE-2016-9387-692f6f1c", "digest": { "threshold": 0.9, "line_hashes": [ "162649287627297576852063731035152415525", "226120177115694592232976601955282060729", "85618242479426270109887864443891666473", "209686564553207354020312973871361104708", "244588284884631190782244829546901289064", "125189853892253328008764467669758377742", "339689915099979973143487541221300521781", "111458785441638967645653322889124458209" ] }, "deprecated": false, "signature_version": "v1" }, { "source": "https://github.com/jasper-software/jasper/commit/d91198abd00fc435a397fe6bad906a4c1748e9cf", "signature_type": "Function", "target": { "file": "src/libjasper/jpc/jpc_dec.c", "function": "jpc_dec_process_siz" }, "id": "CVE-2016-9387-f46d5386", "digest": { "function_hash": "84919795419482091308761414363530504873", "length": 3036.0 }, "deprecated": false, "signature_version": "v1" } ] }