The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.
The product divides a value by zero.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jasper | Jasper_project | * | 1.900.3 (including) |
Red Hat Enterprise Linux 6 | RedHat | jasper-0:1.900.1-21.el6_9 | * |
Red Hat Enterprise Linux 7 | RedHat | jasper-0:1.900.1-30.el7_3 | * |
Jasper | Ubuntu | precise | * |
Jasper | Ubuntu | trusty | * |
Jasper | Ubuntu | vivid/stable-phone-overlay | * |
Jasper | Ubuntu | xenial | * |
Jasper | Ubuntu | yakkety | * |