The jpcdecprocesssiz function in libjasper/jpc/jpcdec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command.
{ "vanir_signatures": [ { "digest": { "length": 1235.0, "function_hash": "94188601995937479999006365181574232397" }, "source": "https://github.com/jasper-software/jasper/commit/d8c2604cd438c41ec72aff52c16ebd8183068020", "signature_type": "Function", "target": { "function": "jpc_siz_getparms", "file": "src/libjasper/jpc/jpc_cs.c" }, "deprecated": false, "signature_version": "v1", "id": "CVE-2016-8692-0cce8fe9" } ] }