PT-2020-8032 · Mageia · Ghostscript+1

Publicado

2016-11-03

·

Atualizado

2016-11-03

·

CVE-2016-3181

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
A specially crafted JPEG2000 image file can force Out-Of-Bounds Read in opj tcd free tile() (CVE-2016-3181).
A specially crafted JPEG2000 image file can force Heap Corruption in opj free() (CVE-2016-3182).
A specially crafted JPEG2000 image file can force Out-Of-Bounds Read in sycc422 to rgb() (CVE-2016-3183).
OpenJPEG Heap Buffer Overflow in function color cmyk to rgb() in color.c (CVE-2016-4796).
OpenJPEG division-by-zero in function opj tcd init tile() in tcd.c (CVE-2016-4797).
Heap-based buffer overflow in the opj dwt interleave v function in dwt.c in OpenJPEG allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data (CVE-2016-5157).
Integer overflow in the opj pi create decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write (CVE-2016-7163).
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s (CVE-2016-7445).
A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an out of bound heap write resulting in heap corruption leading to arbitrary code execution (CVE-2016-8332).
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2016-3181
MGASA-2016-0362

Produtos afetados

Ghostscript
Openjpeg2