CVE-2016-3183
published 2017-02-03CVE-2016-3183: The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted…
PriorityP423medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
3.44%
87.6th percentile
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.1.1-1 (bookworm) | openjpeg2 2.1.1-1 (bookworm) |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.1-1 | 2.1.1-1 |
| uclouvain | openjpeg | <= 2.1.0 | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg: Out-of-bounds read in sycc422_to_rgb function
vendor_redhat·2016-03-14·CVSS 5.5
CVE-2016-3183 [MEDIUM] CWE-125 openjpeg: Out-of-bounds read in sycc422_to_rgb function
openjpeg: Out-of-bounds read in sycc422_to_rgb function
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-3183: openjpeg2 - The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows rem...
vendor_debian·2016·CVSS 5.5
CVE-2016-3183 [MEDIUM] CVE-2016-3183: openjpeg2 - The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows rem...
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1)
GHSA
GHSA-55fp-6c46-gr3x: The sycc422_t_rgb function in common/color
ghsa_unreviewed·2022-05-13
CVE-2016-3183 [MEDIUM] CWE-125 GHSA-55fp-6c46-gr3x: The sycc422_t_rgb function in common/color
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
OSV
gnutls26 vulnerability
osv·2017-03-20·CVSS 7.5
CVE-2016-8610 gnutls26 vulnerability
gnutls26 vulnerability
USN-3183-1 fixed CVE-2016-8610 in GnuTLS in Ubuntu 16.04 LTS and Ubuntu
16.10. This update provides the corresponding update for Ubuntu 12.04 LTS
and Ubuntu 14.04 LTS.
Original advisory details:
Stefan Buehler discovered that GnuTLS incorrectly verified the serial
length of OCSP responses. A remote attacker could possibly use this issue
to bypass certain certificate validation measures. This issue only applied
to Ubuntu 16.04 LTS. (CVE-2016-7444)
Shi Lei discovered that GnuTLS incorrectly handled certain warning alerts.
A remote attacker could possibly use this issue to cause GnuTLS to hang,
resulting in a denial of service. This issue has only been addressed in
Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-8610)
It was discovered that GnuTLS incorrectly decoded
OSV
CVE-2016-3183: The sycc422_t_rgb function in common/color
osv·2017-02-03·CVSS 5.5
CVE-2016-3183 [MEDIUM] CVE-2016-3183: The sycc422_t_rgb function in common/color
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
No detection rules found.
No public exploits indexed.
arXiv
jTrans: Jump-Aware Transformer for Binary Code Similarity
arxiv_fulltext·2022-05-25
jTrans: Jump-Aware Transformer for Binary Code Similarity
: Jump-Aware Transformer for Binary Code Similarity Detection
Hao Wang
Both authors contributed equally to this research.
Institute for Network Sciences and Cyberspace, Tsinghua University
Tsinghua University, BNRist
Beijing
China
[email protected]
Wenjie Qu
[1]
Huazhong University of Science and Technology
Wuhan
China
[email protected]
Gilad Katz
Ben-Gurion University of the Negev
Be'er Sheva
Israel
[email protected]
Wenyu Zhu
Tsinghua University, BNRist
Beijing
China
[email protected]
Zeyu Gao
University of Science and Technology of China, Hefei, China
Hefei
China
[email protected]
Han Qiu
[2]
Tsinghua University
Beijing
China
[email protected]
Jianwei Zhuge
[2]
Tsinghua Universityy, BNRist
Beijing
China
[email protected].
HackerOne
CVE-2016-3183 OpenJPEG sycc422_to_rgb Out-of-Bounds Read Vulnerability
hackerone·2019-11-12·CVSS 5.5
CVE-2016-3183 [MEDIUM] CVE-2016-3183 OpenJPEG sycc422_to_rgb Out-of-Bounds Read Vulnerability
CVE-2016-3183 OpenJPEG sycc422_to_rgb Out-of-Bounds Read Vulnerability
# CVE-2016-3183 OpenJPEG sycc422_to_rgb Out-of-Bounds Read Vulnerability
## 1. About OpenJPEG
OpenJPEG is an open-source JPEG 2000 codec written in C language. It's widely used in lots of Linux OSes such as Ubuntu, RedHat, Debian, Fedora, and so on. The official repository of the OpenJPEG project is available at [GitHub](https://github.com/uclouvain/openjpeg).
## 2. Credit
This vulnerability was discovered by Ke Liu of Tencent's Xuanwu LAB.
## 3. Testing Environments
+ **OS**: Ubuntu
+ **OpenJPEG**: [0069a2b](https://github.com/uclouvain/openjpeg/archive/0069a2bd2f8055b7edf9699332f4f00ac5351564.zip) (Master version before Mar/14/2016)
+ **Compiler**: Clang
+ **CFLAGS**: ``-g -O0 -fsanitize=address``
## 4. Reproduce
Bugzilla
CVE-2016-3183 openjpeg: Out-of-bounds read in sycc422_to_rgb function
bugzilla·2016-03-15·CVSS 5.5
CVE-2016-3183 [MEDIUM] CVE-2016-3183 openjpeg: Out-of-bounds read in sycc422_to_rgb function
CVE-2016-3183 openjpeg: Out-of-bounds read in sycc422_to_rgb function
n our-of-bounds read vulnerability in sycc422_to_rgb function triggered by specially crafted JPEG2000 image file was found in openjpeg version 2016.03.14.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q1/632
Discussion:
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1317831]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1317830]
Affects: epel-all [bug 1317832]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q1/668
---
Patch: https://github.com/uclouvain/openjpeg/commit/15f081c89650dccee4aa4ae66f614c3fdb268767
---
openjpeg2-2.1.1-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, ple
http://www.openwall.com/lists/oss-security/2016/03/16/17https://bugzilla.redhat.com/show_bug.cgi?id=1317821https://github.com/uclouvain/openjpeg/commit/15f081c89650dccee4aa4ae66f614c3fdb268767https://github.com/uclouvain/openjpeg/issues/726https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FFMOZOF2EI6N2CR23EQ5EATWLQKBMHW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BJM23YERMEC6LCTWBUH7LZURGSLZDFDH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFRD35RIPRCGZA5DKAKHZ62LMP2A5UT7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPMDEUIMHTLKMHELDL4F4HZ7X4Y34JEB/https://security.gentoo.org/glsa/201612-26https://www.oracle.com/security-alerts/cpujul2020.htmlhttp://www.openwall.com/lists/oss-security/2016/03/16/17https://bugzilla.redhat.com/show_bug.cgi?id=1317821https://github.com/uclouvain/openjpeg/commit/15f081c89650dccee4aa4ae66f614c3fdb268767https://github.com/uclouvain/openjpeg/issues/726https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FFMOZOF2EI6N2CR23EQ5EATWLQKBMHW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BJM23YERMEC6LCTWBUH7LZURGSLZDFDH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFRD35RIPRCGZA5DKAKHZ62LMP2A5UT7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPMDEUIMHTLKMHELDL4F4HZ7X4Y34JEB/https://security.gentoo.org/glsa/201612-26https://www.oracle.com/security-alerts/cpujul2020.html
2017-02-03
Published