CVE-2016-9560

Source
https://cve.org/CVERecord?id=CVE-2016-9560
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9560.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-9560
Downstream
Related
Published
2017-02-15T19:59:01.173Z
Modified
2026-02-07T22:03:34.931543Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Stack-based buffer overflow in the jpctsfbgetbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image.

References

Affected packages

Git / github.com/jasper-software/jasper

Affected ranges

Type
GIT
Repo
https://github.com/jasper-software/jasper
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
mdadams-clang-issue
version-1.*
version-1.900.1
version-1.900.10
version-1.900.11
version-1.900.12
version-1.900.13
version-1.900.14
version-1.900.15
version-1.900.16
version-1.900.17
version-1.900.18
version-1.900.19
version-1.900.2
version-1.900.20
version-1.900.21
version-1.900.22
version-1.900.23
version-1.900.24
version-1.900.25
version-1.900.26
version-1.900.27
version-1.900.28
version-1.900.29
version-1.900.3
version-1.900.4
version-1.900.5
version-1.900.6
version-1.900.7
version-1.900.8
version-1.900.9

Database specific

vanir_signatures
[
    {
        "deprecated": false,
        "source": "https://github.com/jasper-software/jasper/commit/1abc2e5a401a4bf1d5ca4df91358ce5df111f495",
        "id": "CVE-2016-9560-2c2ab8d1",
        "target": {
            "file": "src/libjasper/jpc/jpc_dec.c",
            "function": "jpc_dec_tileinit"
        },
        "digest": {
            "function_hash": "175780790939713017166030104739135087449",
            "length": 7222.0
        },
        "signature_type": "Function",
        "signature_version": "v1"
    },
    {
        "deprecated": false,
        "source": "https://github.com/jasper-software/jasper/commit/1abc2e5a401a4bf1d5ca4df91358ce5df111f495",
        "id": "CVE-2016-9560-d53e43ce",
        "target": {
            "file": "src/libjasper/jpc/jpc_dec.c"
        },
        "digest": {
            "line_hashes": [
                "213472728717264795323337321314463496991",
                "34944051443844679150364108266102405752",
                "213113553643681384229018291800625340333",
                "309304087652309107944001807487660727374"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9560.json"

Git / github.com/mdadams/jasper

Affected ranges

Type
GIT
Repo
https://github.com/mdadams/jasper
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
mdadams-clang-issue
version-1.*
version-1.900.1
version-1.900.10
version-1.900.11
version-1.900.12
version-1.900.13
version-1.900.14
version-1.900.15
version-1.900.16
version-1.900.17
version-1.900.18
version-1.900.19
version-1.900.2
version-1.900.20
version-1.900.21
version-1.900.22
version-1.900.23
version-1.900.24
version-1.900.25
version-1.900.26
version-1.900.27
version-1.900.28
version-1.900.29
version-1.900.3
version-1.900.4
version-1.900.5
version-1.900.6
version-1.900.7
version-1.900.8
version-1.900.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9560.json"