The jpcirct and jpciict functions in jpc_mct.c in JasPer before 1.900.14 allow remote attackers to cause a denial of service (assertion failure).
{ "vanir_signatures": [ { "target": { "file": "src/libjasper/jpc/jpc_dec.c", "function": "jpc_dec_tiledecode" }, "signature_version": "v1", "digest": { "length": 3049.0, "function_hash": "261632930046479513554722234066556890270" }, "id": "CVE-2016-9389-bedc6754", "deprecated": false, "signature_type": "Function", "source": "https://github.com/jasper-software/jasper/commit/dee11ec440d7908d1daf69f40a3324b27cf213ba" }, { "target": { "file": "src/libjasper/base/jas_image.c" }, "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "241303558033548865830554046166520438091", "216526407651275680166081834085998805491", "108689258764984063463474800061613878688", "89372554593581095882581861032257605881", "142859876017945854376485930451138444135", "78015001333852801620482671946494780940", "71780159437463369330704703419535261235" ] }, "id": "CVE-2016-9389-e469061d", "deprecated": false, "signature_type": "Line", "source": "https://github.com/jasper-software/jasper/commit/dee11ec440d7908d1daf69f40a3324b27cf213ba" }, { "target": { "file": "src/libjasper/jpc/jpc_dec.c" }, "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "235117054589718002123210316905764196476", "225577507812648049050607671598735025280", "12338734913713525394635968919617706449", "8132114298438502021076254312154883115", "16027635109708654144313138821962911238", "183141350026983836306099345388775477522", "237012920520242573996724710966998023245", "265303255597738619663178691719278722686" ] }, "id": "CVE-2016-9389-f9e0bc85", "deprecated": false, "signature_type": "Line", "source": "https://github.com/jasper-software/jasper/commit/dee11ec440d7908d1daf69f40a3324b27cf213ba" }, { "target": { "file": "src/libjasper/include/jasper/jas_image.h" }, "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "338976520416505147663599087249732400051", "197938108097747698244503602632838242565", "281515638190587300448162587186962847492", "219864176890331443438815251979133473226", "56684480946414736860630488449273837579", "317368969495954525661247866391495621597", "205785960194076628002050040816252376520" ] }, "id": "CVE-2016-9389-fac9766a", "deprecated": false, "signature_type": "Line", "source": "https://github.com/jasper-software/jasper/commit/dee11ec440d7908d1daf69f40a3324b27cf213ba" } ] }