The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image.
https://bugzilla.redhat.com/show_bug.cgi?id=1385499
https://access.redhat.com/errata/RHSA-2017:1208
http://www.securityfocus.com/bid/93834
http://www.openwall.com/lists/oss-security/2016/10/23/9