« List of all CVEs

CVE-2016-1577

Published: 4/13/2016 Last updated: 8/5/2024 Reserved: 1/12/2016

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137.

CNA assigner: canonical (cc1ad9ee-3454-478d-9317-d3e869d708bc) Requested by: n/a

Opam packages affected (1)

grib

Products affected (1)

Product Vendor Version
n/a n/a 12.2(2)BX1

References (12)