PT-2017-8531 · Openjpeg+2 · Openjpeg+2

Published

2016-07-09

·

Updated

2022-04-07

·

CVE-2016-4797

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenJPEG versions prior to 2.1.1
Description A divide-by-zero issue in the opj tcd init tile function in tcd.c allows remote attackers to cause a denial of service, resulting in an application crash, via a crafted jp2 file. This issue exists due to an incorrect fix for a previous problem.
Recommendations For versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the processing of crafted jp2 files to minimize the risk of exploitation.

Fix

DoS

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1743
CVE-2016-4797
MGASA-2016-0362
SUSE-SU-2022:1129-1

Affected Products

Alt Linux
Openjpeg
Suse