CVE-2016-9118
published 2016-10-30CVE-2016-9118: Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
PriorityP430medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
3.12%
86.4th percentile
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.1.2-1.2 (bookworm) | openjpeg2 2.1.2-1.2 (bookworm) |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.2 | 2.1.2-1.2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.2 | 2.1.2-1.2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.2 | 2.1.2-1.2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.2 | 2.1.2-1.2 |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6c7-9x7r-9r3f: Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert
ghsa_unreviewed·2022-05-13
CVE-2016-9118 [MEDIUM] CWE-119 GHSA-f6c7-9x7r-9r3f: Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
OSV
CVE-2016-9118: Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert
osv·2016-10-30·CVSS 5.3
CVE-2016-9118 [MEDIUM] CVE-2016-9118: Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
Red Hat
openjpeg2: Multiple security issues
vendor_redhat·2016-10-27·CVSS 5.3
CVE-2016-9118 [MEDIUM] openjpeg2: Multiple security issues
openjpeg2: Multiple security issues
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-9118: openjpeg2 - Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 ...
vendor_debian·2016·CVSS 5.3
CVE-2016-9118 [MEDIUM] CVE-2016-9118: openjpeg2 - Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 ...
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
Scope: local
bookworm: resolved (fixed in 2.1.2-1.2)
bullseye: resolved (fixed in 2.1.2-1.2)
forky: resolved (fixed in 2.1.2-1.2)
sid: resolved (fixed in 2.1.2-1.2)
trixie: resolved (fixed in 2.1.2-1.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: Multiple security issues [fedora-all]
bugzilla·2016-10-31·CVSS 7.5
CVE-2016-9112 [HIGH] CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: Multiple security issues [fedora-all]
CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: Multiple security issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
Bugzilla
CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 mingw-openjpeg2: openjpeg2: Multiple security issues [fedora-all]
bugzilla·2016-10-31·CVSS 7.5
CVE-2016-9112 [HIGH] CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 mingw-openjpeg2: openjpeg2: Multiple security issues [fedora-all]
CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 mingw-openjpeg2: openjpeg2: Multiple security issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: Multiple security issues
bugzilla·2016-10-31·CVSS 7.5
CVE-2016-9113 [HIGH] CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: Multiple security issues
CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: Multiple security issues
Multiple issues in openjpeg2 were discovered by fuzzing. An attacker could create a malicious file that, when processed by openjpeg2 command line tools, could cause a crash or, potentially, code execution.
See comment 4 for individual details.
Discussion:
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1390235]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1390234]
---
Created openjpeg2 tracking bugs for this issue:
Affects: epel-all [bug 1381271]
---
Adding multiple other issues which received CVEs.
CVE-2016-9113: NULL pointer dereference in function imagetobmp
https://github.com/uclouvain/openj
Bugzilla
CVE-2016-8332 CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: various flaws [epel-all]
bugzilla·2016-10-03·CVSS 7.5
CVE-2016-8332 [HIGH] CVE-2016-8332 CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: various flaws [epel-all]
CVE-2016-8332 CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
http://www.debian.org/security/2017/dsa-4013http://www.securityfocus.com/bid/93976https://github.com/uclouvain/openjpeg/issues/861https://security.gentoo.org/glsa/201710-26http://www.debian.org/security/2017/dsa-4013http://www.securityfocus.com/bid/93976https://github.com/uclouvain/openjpeg/issues/861https://security.gentoo.org/glsa/201710-26
2016-10-30
Published