PT-2016-3334 · Openjpeg+3 · Openjpeg+3
Published
2016-10-29
·
Updated
2022-10-07
·
CVE-2016-9112
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenJPEG version 2.1.2
Description
The issue is related to a division by zero error in the OpenJPEG library, which is used for image encoding and decoding. This error can be exploited by a remote attacker to cause a denial of service. The problem is specifically located in the
opj pi next cprl function in the openjp2/pi.c file at line 523.Recommendations
For OpenJPEG version 2.1.2, consider applying a patch or fix that addresses the division by zero error in the
opj pi next cprl function to prevent potential denial of service attacks. As a temporary workaround, consider restricting the use of the opj pi next cprl function until a patch is available.Exploit
Fix
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Openjpeg
Suse
Ubuntu