CVE-2016-7445
published 2016-10-03CVE-2016-7445: convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving…
PriorityP433high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.19%
89.8th percentile
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.1.2-1 (bookworm) | openjpeg2 2.1.2-1 (bookworm) |
| opensuse | leap | — | — |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
| uclouvain | openjpeg | <= 2.1.1 | — |
| uclouvain | openjpeg | >= 0 < 1:1.5.2-3.1ubuntu0.1~esm2 | 1:1.5.2-3.1ubuntu0.1~esm2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
openjpeg vulnerabilities
osv·2022-10-07·CVSS 6.5
CVE-2016-7445 [MEDIUM] openjpeg vulnerabilities
openjpeg vulnerabilities
It was discovered that OpenJPEG did not properly handle PNM
headers, resulting in a null pointer dereference. A remote
attacker could possibly use this issue to cause a denial of
service (DoS). (CVE-2016-7445)
It was discovered that OpenJPEG incorrectly handled certain
image files resulting in division by zero. A remote attacker
could possibly use this issue to cause a denial of service
(DoS). (CVE-2016-9112 and CVE-2016-10506)
It was discovered that OpenJPEG incorrectly handled converting
certain image files resulting in a stack buffer overflow. A
remote attacker could possibly use this issue to cause a
denial of service (DoS). (CVE-2017-17479)
It was discovered that OpenJPEG incorrectly handled converting
PNM image files resulting in a null pointer dereferenc
GHSA
GHSA-vj8h-cvfh-v55g: convert
ghsa_unreviewed·2022-05-13
CVE-2016-7445 [HIGH] CWE-476 GHSA-vj8h-cvfh-v55g: convert
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
OSV
CVE-2016-7445: convert
osv·2016-10-03·CVSS 7.5
CVE-2016-7445 [HIGH] CVE-2016-7445: convert
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
Ubuntu
OpenJPEG vulnerabilities
vendor_ubuntu·2022-10-07·CVSS 6.5
CVE-2016-10506 [MEDIUM] OpenJPEG vulnerabilities
Title: OpenJPEG vulnerabilities
Summary: OpenJPEG could be made to crash if it opened a specially crafted
file.
It was discovered that OpenJPEG did not properly handle PNM
headers, resulting in a null pointer dereference. A remote
attacker could possibly use this issue to cause a denial of
service (DoS). (CVE-2016-7445)
It was discovered that OpenJPEG incorrectly handled certain
image files resulting in division by zero. A remote attacker
could possibly use this issue to cause a denial of service
(DoS). (CVE-2016-9112 and CVE-2016-10506)
It was discovered that OpenJPEG incorrectly handled converting
certain image files resulting in a stack buffer overflow. A
remote attacker could possibly use this issue to cause a
denial of service (DoS). (CVE-2017-17479)
It was discovered that OpenJP
Debian
CVE-2016-7445: openjpeg2 - convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of ...
vendor_debian·2016·CVSS 7.5
CVE-2016-7445 [HIGH] CVE-2016-7445: openjpeg2 - convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of ...
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
Scope: local
bookworm: resolved (fixed in 2.1.2-1)
bullseye: resolved (fixed in 2.1.2-1)
forky: resolved (fixed in 2.1.2-1)
sid: resolved (fixed in 2.1.2-1)
trixie: resolved (fixed in 2.1.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c
bugzilla·2016-09-19·CVSS 7.5
CVE-2016-7445 [HIGH] CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c
CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c
A null pointer dereference vulnerability was found in the convert.c function of openjpeg2. This could cause the application to crash when parsing a maliciously crafted file.
References:
http://seclists.org/oss-sec/2016/q3/546
Upstream bug:
https://github.com/uclouvain/openjpeg/issues/843
Discussion:
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1377347]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1377346]
Affects: epel-all [bug 1377348]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual
Bugzilla
CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c [fedora-all]
bugzilla·2016-09-19·CVSS 7.5
CVE-2016-7445 [HIGH] CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c [fedora-all]
CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c [epel-all]
bugzilla·2016-09-19·CVSS 7.5
CVE-2016-7445 [HIGH] CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c [epel-all]
CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2016-7445 mingw-openjpeg2: openjpeg2: Null pointer dereference in convert.c [fedora-all]
bugzilla·2016-09-19·CVSS 7.5
CVE-2016-7445 [HIGH] CVE-2016-7445 mingw-openjpeg2: openjpeg2: Null pointer dereference in convert.c [fedora-all]
CVE-2016-7445 mingw-openjpeg2: openjpeg2: Null pointer dereference in convert.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
http://lists.opensuse.org/opensuse-updates/2016-09/msg00109.htmlhttp://www.openwall.com/lists/oss-security/2016/09/18/4http://www.openwall.com/lists/oss-security/2016/09/18/6http://www.securityfocus.com/bid/93040https://github.com/uclouvain/openjpeg/blob/openjpeg-2.1/CHANGELOG.mdhttps://github.com/uclouvain/openjpeg/issues/843https://security.gentoo.org/glsa/201612-26http://lists.opensuse.org/opensuse-updates/2016-09/msg00109.htmlhttp://www.openwall.com/lists/oss-security/2016/09/18/4http://www.openwall.com/lists/oss-security/2016/09/18/6http://www.securityfocus.com/bid/93040https://github.com/uclouvain/openjpeg/blob/openjpeg-2.1/CHANGELOG.mdhttps://github.com/uclouvain/openjpeg/issues/843https://security.gentoo.org/glsa/201612-26
2016-10-03
Published