Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.
References
Configurations
History
No history.
Information
Published : 2017-03-23 18:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-9262
Mitre link : CVE-2016-9262
CVE.ORG link : CVE-2016-9262
JSON object : View
Products Affected
jasper_project
- jasper
CWE
CWE-190
Integer Overflow or Wraparound