Back to Database
Status published
High
CVE-2016-10248
The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows...
Vulnerability Description
The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-10248
Credits & Attribution
No credits recorded in the NVD database.
References
- https://blogs.gentoo.org/ago/2016/10/20/jasper-null-pointer-dereference-in-jpc_tsfb_synthesize-jpc_tsfb-c/
- https://github.com/mdadams/jasper/commit/2e82fa00466ae525339754bb3ab0a0474a31d4bd
- https://access.redhat.com/errata/RHSA-2017:1208
- http://www.securityfocus.com/bid/93797
- https://usn.ubuntu.com/3693-1/
More from jasper project
View All →CVE-2022-40755
JasPer 3.0.6 allows denial of service via a reachable assertion...
Medium
5.5
CVE-2021-3272
jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a...
Medium
5.5
CVE-2021-27845
A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0...
Medium
5.5
CVE-2018-9252
JasPer 2.0.14 allows denial of service via a reachable assertion...
Medium
6.5
CVE-2018-9154
There is a reachable abort in the function jpc_dec_process_sot in...
High
7.5
Affected Vendor
jasper project
View all reports →Affected Software
jasper
Vulnerable Versions:
0
Timeline
Official Publish:
March 15th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.