Severity
5.5MEDIUM
EPSS
0.3%
top 45.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMay 24

Description

The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDuclouvain/openjpeg< 2.1.1
Debianopenjpeg2< 2.1.1-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wf2g-ww4q-859v: The color_esycc_to_rgb function in bin/common/color2022-05-24
CVEList
CVE-2016-3182: The color_esycc_to_rgb function in bin/common/color2020-02-20
OSV
CVE-2016-3182: The color_esycc_to_rgb function in bin/common/color2020-02-20

📋Vendor Advisories

3
Red Hat
openjpeg: Heap corruption in opj_free function2016-03-14
Red Hat
openjpeg: Out-of-bounds read in opj_tcd_free_tile function2016-03-14
Debian
CVE-2016-3182: openjpeg2 - The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 a...2016

💬Community

2
HackerOne
CVE-2016-3182 OpenJPEG color_esycc_to_rgb Out-of-Bounds Read Vulnerability2019-11-12
Bugzilla
CVE-2016-3182 openjpeg: Heap corruption in opj_free function2016-03-15
CVE-2016-3182 (MEDIUM CVSS 5.5) | The color_esycc_to_rgb function in | cvebase.io