CVE-2016-10507Integer Overflow or Wraparound in Openjpeg

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 29.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 30
Latest updateMay 13

Description

Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5vr5-4x8v-hcfp: Integer overflow vulnerability in the bmp24toimage function in convertbmp2022-05-13
OSV
CVE-2016-10507: Integer overflow vulnerability in the bmp24toimage function in convertbmp2017-08-30
CVEList
CVE-2016-10507: Integer overflow vulnerability in the bmp24toimage function in convertbmp2017-08-30

📋Vendor Advisories

2
Red Hat
openjpeg: Integer overflow in bmp24toimage function in convertbmp.c2017-08-30
Debian
CVE-2016-10507: openjpeg2 - Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in O...2016

💬Community

6
Bugzilla
CVE-2016-10504 CVE-2016-10505 CVE-2016-10506 CVE-2016-10507 mingw-openjpeg: various flaws [fedora-all]2017-08-31
Bugzilla
CVE-2016-10507 openjpeg: Integer overflow in bmp24toimage function in convertbmp.c2017-08-31
Bugzilla
CVE-2016-10504 CVE-2016-10505 CVE-2016-10506 CVE-2016-10507 openjpeg2: various flaws [epel-all]2017-08-31
Bugzilla
CVE-2016-10504 CVE-2016-10505 CVE-2016-10506 CVE-2016-10507 openjpeg: various flaws [fedora-all]2017-08-31
Bugzilla
CVE-2016-10504 CVE-2016-10505 CVE-2016-10506 CVE-2016-10507 openjpeg2: various flaws [fedora-all]2017-08-31
CVE-2016-10507 — Integer Overflow or Wraparound | cvebase