The jpcbitstreamgetbits function in jpc_bs.c in JasPer before 2.0.10 allows remote attackers to cause a denial of service (assertion failure) via a very large integer.
[
{
"digest": {
"line_hashes": [
"196102015073898811297645533749313385048",
"190549514793867061496865254793867049549",
"171839360652686268972686190385272810403",
"50400149924543441238412807462829520889",
"327322110233288906014826537694938170279"
],
"threshold": 0.9
},
"source": "https://github.com/jasper-software/jasper/commit/1e84674d95353c64e5c4c0e7232ae86fd6ea813b",
"target": {
"file": "src/libjasper/jpc/jpc_cs.c"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"id": "CVE-2016-9391-21661ce8"
},
{
"digest": {
"line_hashes": [
"9972650022297922309487281288480744632",
"1489525600137566990126885294519030176",
"149890288200170398430171093976719239093",
"237044679106646705559528529513431051677",
"39002238908207410680545806976024079133",
"194392780604242950240920179815254504841",
"189432908879894595340330197054530181359",
"158542315238795176845374494279664169498"
],
"threshold": 0.9
},
"source": "https://github.com/jasper-software/jasper/commit/1e84674d95353c64e5c4c0e7232ae86fd6ea813b",
"target": {
"file": "src/libjasper/jpc/jpc_bs.c"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"id": "CVE-2016-9391-3bccb112"
},
{
"digest": {
"function_hash": "243069738599967674544252627031642253684",
"length": 584.0
},
"source": "https://github.com/jasper-software/jasper/commit/1e84674d95353c64e5c4c0e7232ae86fd6ea813b",
"target": {
"file": "src/libjasper/jpc/jpc_cs.c",
"function": "jpc_qcd_dumpparms"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"id": "CVE-2016-9391-47370895"
},
{
"digest": {
"function_hash": "246779780621125895923085892503686991580",
"length": 312.0
},
"source": "https://github.com/jasper-software/jasper/commit/1e84674d95353c64e5c4c0e7232ae86fd6ea813b",
"target": {
"file": "src/libjasper/jpc/jpc_bs.c",
"function": "jpc_bitstream_putbits"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"id": "CVE-2016-9391-5753ac98"
},
{
"digest": {
"function_hash": "185861260289023515017114181088663291182",
"length": 249.0
},
"source": "https://github.com/jasper-software/jasper/commit/1e84674d95353c64e5c4c0e7232ae86fd6ea813b",
"target": {
"file": "src/libjasper/jpc/jpc_bs.c",
"function": "jpc_bitstream_getbits"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"id": "CVE-2016-9391-7f26e6d9"
}
]