From URL: Description =========== Heap-use-after-free vulnerability in jasper-2.0.8. The vulnerability exists in code responsible for re-encoding the decoded input image file to a JP2 image. The vulnerability is caused by not setting related pointers to be null after the pointers are freed (i.e. missing Setting-Pointer-Null operations after free). The vulnerability can further cause double-free. This bug has been assigned to CVE-2016-9591 References ========== https://github.com/mdadams/jasper/issues/105 Reproducible: Didn't try
Added to an existing GLSA.
This issue was resolved and addressed in GLSA 201707-07 at https://security.gentoo.org/glsa/201707-07 by GLSA coordinator Thomas Deutschmann (whissi).