Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2016-2116

MEDIUM severity · CVSS 5.7 · CWE-399
5.7CVSS MEDIUM

Summary

Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredLow
User interactionRequired
Confidentiality impactNone
Integrity impactNone
Availability impactHigh
Exploit probability (EPSS)3%

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.