Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.debian.org/security/2016/dsa-3508 | vendor advisory |
http://www.openwall.com/lists/oss-security/2016/03/03/12 | mailing list |
https://bugs.launchpad.net/ubuntu/+source/jasper/+bug/1547865 | |
http://www.ubuntu.com/usn/USN-2919-1 | vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1208 | vendor advisory |
http://www.securityfocus.com/bid/84133 | vdb entry |