The jasseq2dcreate function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
[
{
"id": "CVE-2016-9390-21779471",
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "src/libjasper/jpc/jpc_cs.c",
"function": "jpc_siz_getparms"
},
"source": "https://github.com/jasper-software/jasper/commit/ba2b9d000660313af7b692542afbd374c5685865",
"digest": {
"length": 1656.0,
"function_hash": "45008450416977911492424407671749520564"
},
"signature_version": "v1"
},
{
"id": "CVE-2016-9390-a084f0ab",
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "src/libjasper/jpc/jpc_cs.c"
},
"source": "https://github.com/jasper-software/jasper/commit/ba2b9d000660313af7b692542afbd374c5685865",
"digest": {
"line_hashes": [
"234752286057864962727890294762781699511",
"24833995471777026640290151728442320809",
"179898142459622662779942610421325509296",
"90306631920095266507461818008189116624"
],
"threshold": 0.9
},
"signature_version": "v1"
}
]