CVE-2016-8654
HIGHCVSS 7.8/10EPSS 1.91%
Last modified
CVE-2016-8654 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.. EPSS estimates a 1.91% chance of exploitation in the next 30 days.
Description
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jasper Project | Jasper | < 2.0.0 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.3 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- https://www.securityfocus.com/bid/94583Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1208Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8654Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/mdadams/jasper/commit/4a59cfaf9ab3d48fca4a15c0d2674bf7138e3d1aPatch, Third Party Advisory
- https://github.com/mdadams/jasper/issues/93Exploit, Third Party Advisory
- https://github.com/mdadams/jasper/issues/94Exploit, Third Party Advisory
- https://www.debian.org/security/2017/dsa-3785Third Party Advisory
- https://www.securityfocus.com/bid/94583Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1208Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8654Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/mdadams/jasper/commit/4a59cfaf9ab3d48fca4a15c0d2674bf7138e3d1aPatch, Third Party Advisory
- https://github.com/mdadams/jasper/issues/93Exploit, Third Party Advisory
- https://github.com/mdadams/jasper/issues/94Exploit, Third Party Advisory
- https://www.debian.org/security/2017/dsa-3785Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8654?
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
How severe is CVE-2016-8654?
CVE-2016-8654 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 1.91% probability of exploitation in the next 30 days.
How do I fix CVE-2016-8654?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8648It was found that the Karaf container used by Red Hat JBoss …7.2
- CVE-2016-8649lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows a…
- CVE-2016-8650The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kern…
- CVE-2016-8651An input validation flaw was found in the way OpenShift 3 ha…3.1
- CVE-2016-8652The auth component in Dovecot before 2.2.27, when auth-polic…
- CVE-2016-8653It was found that the JMX endpoint of Red Hat JBoss Fuse 6, …5.3
- CVE-2016-8655Race condition in net/packet/af_packet.c in the Linux kernel…7.8
- CVE-2016-8656Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vul…7
- CVE-2016-8657It was discovered that EAP packages in certain versions of R…
- CVE-2016-8658Stack-based buffer overflow in the brcmf_cfg80211_start_ap f…
- CVE-2016-8659Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which…
- CVE-2016-8660The XFS subsystem in the Linux kernel through 4.8.2 allows l…
Are you affected by CVE-2016-8654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
