CVE-2016-2116: Canonical Ubuntu Linux
Medium severity, CVSS 5.7. EPSS: 3% chance of exploitation in the next 30 days.
Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
- Jasper Project Jasper: up to and including 1.900.1
Published 2016-04-13. Last modified 2026-06-17.