Heap-use-after-free vulnerability in jasper-2.0.8. The vulnerability exists in code responsible for re-encoding the decoded input image file to a JP2 image. The vulnerability is caused by not setting related pointers to be null after the pointers are freed (i.e. missing Setting-Pointer-Null operations after free). The vulnerability can further cause double-free.
This bug has been assigned to CVE-2016-9591
Reproducible: Didn't try
Added to an existing GLSA.
This issue was resolved and addressed in
GLSA 201707-07 at https://security.gentoo.org/glsa/201707-07
by GLSA coordinator Thomas Deutschmann (whissi).