Lucene search

K
ubuntucveUbuntu.comUB:CVE-2016-9395
HistoryMar 23, 2017 - 12:00 a.m.

CVE-2016-9395

2017-03-2300:00:00
ubuntu.com
ubuntu.com
15

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.01 Low

EPSS

Percentile

84.0%

The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows
remote attackers to cause a denial of service (assertion failure) via a
crafted file.

Bugs

Notes

Author Note
mdeslaur this change breaks ABI and can’t be used in stable releases. We will not be fixing this issue. Marking as ignored.

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.01 Low

EPSS

Percentile

84.0%