PatchSiren cyber security CVE debrief
CVE-2016-8692 Debian CVE debrief
CVE-2016-8692 is a denial-of-service vulnerability in JasPer’s JPEG 2000 decoder path. A crafted BMP image with an abnormal YRsiz value can trigger a divide-by-zero in jpc_dec_process_siz, causing the imginfo command to crash. The issue is tracked as CWE-369 and affects JasPer versions before 1.900.4.
- Vendor
- Debian
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
Teams that ship or operate JasPer/libjasper, especially environments listed by NVD as affected (Debian 8.0 and Fedora 25), and anyone allowing imginfo to process untrusted image files.
Technical summary
NVD describes a divide-by-zero condition in libjasper/jpc/jpc_dec.c, specifically in jpc_dec_process_siz, when processing a crafted BMP image with a problematic YRsiz value. The result is an application crash rather than code execution or data corruption. NVD assigns CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating user interaction is required and the primary impact is availability.
Defensive priority
Medium. The issue is a crash-only denial of service, but it affects image parsing of untrusted content and is easy to miss in automated workflows.
Recommended defensive actions
- Upgrade JasPer to version 1.900.4 or later, or apply the vendor-packaged fix for your distribution.
- Review Debian and Red Hat/Fedora security advisories for the specific package build you deploy and confirm patched versions are installed.
- Restrict where untrusted BMP or other external image files can be processed, and run image-handling jobs with least privilege and process isolation.
- Monitor for crashes or abnormal termination in imginfo or other JasPer-based tooling, especially when handling externally supplied files.
Evidence notes
The NVD record states that jpc_dec_process_siz in libjasper/jpc/jpc_dec.c can crash on a crafted BMP image via a divide-by-zero tied to YRsiz, with CWE-369 and CVSS 3.0 AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. NVD lists JasPer versions through 1.900.3 as vulnerable and includes Debian 8.0 and Fedora 25 CPEs. Public disclosure and follow-on remediation references include oss-security posts from 2016-08-23 and 2016-10-16, Gentoo’s advisory/blog, Debian DSA-3785, Red Hat RHSA-2017:1208, Red Hat bug 1385502, and the upstream patch reference in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8692 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8692
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8692 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8692
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1208
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blogs.gentoo.org/ago/2016/10/16/jasper-two-divide-by-zero-in-jpc_dec_process_siz-jpc_dec-c/
[email protected] - Exploit, Patch, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.