The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
https://usn.ubuntu.com/3693-1/
https://github.com/mdadams/jasper/issues/32
https://access.redhat.com/errata/RHSA-2017:1208
http://www.securityfocus.com/bid/95865