The jp2_colr_destroy function in jp2_cod.c in JasPer before 1.900.13 allows remote attackers to cause a denial of service (NULL pointer dereference) by leveraging incorrect cleanup of JP2 box data on error. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8887.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jasper | Jasper_project | * | 1.900.12 (including) |
Jasper | Ubuntu | precise | * |
Jasper | Ubuntu | trusty | * |
Jasper | Ubuntu | vivid/stable-phone-overlay | * |
Jasper | Ubuntu | xenial | * |
Jasper | Ubuntu | yakkety | * |