CVE-2016-3182
published 2020-02-20CVE-2016-3182: The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.52%
71.8th percentile
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.1.1-1 (bookworm) | openjpeg2 2.1.1-1 (bookworm) |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| uclouvain | openjpeg | < 2.1.1 | 2.1.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg: Heap corruption in opj_free function
vendor_redhat·2016-03-14·CVSS 5.5
CVE-2016-3182 [MEDIUM] CWE-416 openjpeg: Heap corruption in opj_free function
openjpeg: Heap corruption in opj_free function
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Red Hat
openjpeg: Out-of-bounds read in opj_tcd_free_tile function
vendor_redhat·2016-03-14·CVSS 5.5
CVE-2016-3181 [MEDIUM] CWE-125 openjpeg: Out-of-bounds read in opj_tcd_free_tile function
openjpeg: Out-of-bounds read in opj_tcd_free_tile function
[REJECTED CVE] An out-of-bounds read vulnerability in opj_tcd_free_tile function causing segmentation fault triggered by specially crafted JPEG2000 image file was found in openjpeg version 2016.03.14.
Statement: This flaw was found to be a duplicate of CVE-2016-3182. Please see https://access.redhat.com/security/cve/CVE-2016-3182 for information about affected products and security errata.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-3182: openjpeg2 - The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 a...
vendor_debian·2016·CVSS 5.5
CVE-2016-3182 [MEDIUM] CVE-2016-3182: openjpeg2 - The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 a...
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1)
GHSA
GHSA-wf2g-ww4q-859v: The color_esycc_to_rgb function in bin/common/color
ghsa_unreviewed·2022-05-24
CVE-2016-3182 [MEDIUM] GHSA-wf2g-ww4q-859v: The color_esycc_to_rgb function in bin/common/color
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
GHSA
GHSA-jjw9-m7w7-qm6w: DO NOT USE THIS CANDIDATE NUMBER
ghsa_unreviewed·2022-05-24·CVSS 5.5
CVE-2016-3181 [MEDIUM] GHSA-jjw9-m7w7-qm6w: DO NOT USE THIS CANDIDATE NUMBER
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3182. Reason: This candidate is a duplicate of CVE-2016-3182. Notes: All CVE users should reference CVE-2016-3182 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
OSV
CVE-2016-3182: The color_esycc_to_rgb function in bin/common/color
osv·2020-02-20·CVSS 5.5
CVE-2016-3182 [MEDIUM] CVE-2016-3182: The color_esycc_to_rgb function in bin/common/color
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2016-3182 OpenJPEG color_esycc_to_rgb Out-of-Bounds Read Vulnerability
hackerone·2019-11-12·CVSS 5.5
CVE-2016-3182 [MEDIUM] CVE-2016-3182 OpenJPEG color_esycc_to_rgb Out-of-Bounds Read Vulnerability
CVE-2016-3182 OpenJPEG color_esycc_to_rgb Out-of-Bounds Read Vulnerability
# CVE-2016-3182 OpenJPEG color_esycc_to_rgb Out-of-Bounds Read Vulnerability
## 1. About OpenJPEG
OpenJPEG is an open-source JPEG 2000 codec written in C language. It's widely used in lots of Linux OSes such as Ubuntu, RedHat, Debian, Fedora, and so on. The official repository of the OpenJPEG project is available at [GitHub](https://github.com/uclouvain/openjpeg).
## 2. Credit
This vulnerability was discovered by Ke Liu of Tencent's Xuanwu LAB.
## 3. Testing Environments
+ **OS**: Ubuntu
+ **OpenJPEG**: [0069a2b](https://github.com/uclouvain/openjpeg/archive/0069a2bd2f8055b7edf9699332f4f00ac5351564.zip) (Master version before Mar/14/2016)
+ **Compiler**: Clang
+ **CFLAGS**: ``-g -O0 -fsanitize=address``
## 4. R
Bugzilla
CVE-2016-3181 openjpeg: Out-of-bounds read in opj_tcd_free_tile function
bugzilla·2016-03-15·CVSS 5.5
CVE-2016-3181 [MEDIUM] CVE-2016-3181 openjpeg: Out-of-bounds read in opj_tcd_free_tile function
CVE-2016-3181 openjpeg: Out-of-bounds read in opj_tcd_free_tile function
An out-of-bounds read vulnerability in opj_tcd_free_tile function causing segmentation fault triggered by specially crafted JPEG2000 image file was found in openjpeg version 2016.03.14.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q1/630
Discussion:
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1317831]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1317830]
Affects: epel-all [bug 1317832]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q1/666
---
Upstream report: https://github.com/uclouvain/openjpeg/issues/724
---
openjpeg2-2.1.1-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persi
Bugzilla
CVE-2016-3182 openjpeg: Heap corruption in opj_free function
bugzilla·2016-03-15·CVSS 5.5
CVE-2016-3182 [MEDIUM] CVE-2016-3182 openjpeg: Heap corruption in opj_free function
CVE-2016-3182 openjpeg: Heap corruption in opj_free function
Double free or heap corruption vulnerability was found in opj_free function triggered by specially crafted JPEG2000 image file was found in openjpeg 2016.03.14.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q1/631
Discussion:
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1317831]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1317830]
Affects: epel-all [bug 1317832]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q1/667
---
Patch: https://github.com/uclouvain/openjpeg/commit/ad593c9e0622e0d8d87228e67e4dbd36243ffd22
---
openjpeg2-2.1.1-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please
http://www.openwall.com/lists/oss-security/2016/03/16/16http://www.openwall.com/lists/oss-security/2016/09/27/1https://bugzilla.redhat.com/show_bug.cgi?id=1317826https://github.com/uclouvain/openjpeg/issues/725http://www.openwall.com/lists/oss-security/2016/03/16/16http://www.openwall.com/lists/oss-security/2016/09/27/1https://bugzilla.redhat.com/show_bug.cgi?id=1317826https://github.com/uclouvain/openjpeg/issues/725
2020-02-20
Published