CVE-2009-5030
published 2012-07-18CVE-2009-5030: The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.06%
89.5th percentile
The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg: Heap memory corruption leading to invalid free by processing certain Gray16 TIFF images
vendor_redhat·2009-07-31·CVSS 6.8
CVE-2009-5030 [MEDIUM] openjpeg: Heap memory corruption leading to invalid free by processing certain Gray16 TIFF images
openjpeg: Heap memory corruption leading to invalid free by processing certain Gray16 TIFF images
The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free."
GHSA
GHSA-5f2v-78x3-pvgj: The tcd_free_encode function in tcd
ghsa_unreviewed·2022-05-02
CVE-2009-5030 [MEDIUM] CWE-119 GHSA-5f2v-78x3-pvgj: The tcd_free_encode function in tcd
The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free."
No detection rules found.
No public exploits indexed.
http://code.google.com/p/openjpeg/issues/detail?id=5http://code.google.com/p/openjpeg/source/detail?r=1703http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082923.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/083105.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1068.htmlhttp://secunia.com/advisories/48781http://secunia.com/advisories/49913http://www.mandriva.com/security/advisories?name=MDVSA-2012:104http://www.openwall.com/lists/oss-security/2012/04/13/5http://www.securityfocus.com/bid/53012https://exchange.xforce.ibmcloud.com/vulnerabilities/74851https://groups.google.com/forum/#%21topic/openjpeg/DLVrRKbTeI0/discussionhttp://code.google.com/p/openjpeg/issues/detail?id=5http://code.google.com/p/openjpeg/source/detail?r=1703http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082923.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/083105.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1068.htmlhttp://secunia.com/advisories/48781http://secunia.com/advisories/49913http://www.mandriva.com/security/advisories?name=MDVSA-2012:104http://www.openwall.com/lists/oss-security/2012/04/13/5http://www.securityfocus.com/bid/53012https://exchange.xforce.ibmcloud.com/vulnerabilities/74851https://groups.google.com/forum/#%21topic/openjpeg/DLVrRKbTeI0/discussion
2012-07-18
Published