PT-2016-7660 · Openjpeg+3 · Openjpeg+3
Yangy-Xiao
·
Publicado
2016-10-30
·
Atualizado
2026-03-29
·
CVE-2016-9116
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenJPEG version 2.1.2
Description
The issue is related to a NULL pointer access in the
imagetopnm function of convert.c at line 2226, specifically when handling jp2 files. This can lead to a Denial of Service. To exploit this, an attacker would need to craft a malicious j2k file and have a user open it.Recommendations
For OpenJPEG version 2.1.2, as a temporary workaround, consider restricting the use of the
imagetopnm function in convert.c until a patch is available. Avoid opening crafted or untrusted j2k files with OpenJPEG version 2.1.2 to minimize the risk of exploitation.Exploit
Correção
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Openjpeg
Suse