CVE-2016-2116
—CVSS 3.0
5.7 medium
EPSS
3%p86
Published
()
Modified
Description
Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
- Vendors
- canonicaljasper project
- Products
- ubuntu linux, jasper
- Weakness
- CWE-399
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.