CVE-2016-9572
published 2018-08-01CVE-2016-9572: A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the…
PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
2.17%
80.3th percentile
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openjpeg2 | < openjpeg2 2.1.2-1.1 (bookworm) | openjpeg2 2.1.2-1.1 (bookworm) |
| the_openjpeg_project | openjpeg | — | — |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.1 | 2.1.2-1.1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.1 | 2.1.2-1.1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.1 | 2.1.2-1.1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.1 | 2.1.2-1.1 |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg: NULL pointer dereference in input decoding
vendor_redhat·2016-10-28·CVSS 5.9
CVE-2016-9572 [MEDIUM] CWE-476 openjpeg: NULL pointer dereference in input decoding
openjpeg: NULL pointer dereference in input decoding
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-9572: openjpeg2 - A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded cert...
vendor_debian·2016·CVSS 5.9
CVE-2016-9572 [MEDIUM] CVE-2016-9572: openjpeg2 - A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded cert...
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
Scope: local
bookworm: resolved (fixed in 2.1.2-1.1)
bullseye: resolved (fixed in 2.1.2-1.1)
forky: resolved (fixed in 2.1.2-1.1)
sid: resolved (fixed in 2.1.2-1.1)
trixie: resolved (fixed in 2.1.2-1.1)
GHSA
GHSA-3fxp-m3gr-pfvm: A NULL pointer dereference flaw was found in the way openjpeg 2
ghsa_unreviewed·2022-05-13
CVE-2016-9572 [MEDIUM] CWE-476 GHSA-3fxp-m3gr-pfvm: A NULL pointer dereference flaw was found in the way openjpeg 2
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
OSV
CVE-2016-9572: A NULL pointer dereference flaw was found in the way openjpeg 2
osv·2018-08-01·CVSS 6.5
CVE-2016-9572 [MEDIUM] CVE-2016-9572: A NULL pointer dereference flaw was found in the way openjpeg 2
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9573 CVE-2016-9572 openjpeg2: various flaws [epel-6]
bugzilla·2016-12-08·CVSS 5.9
CVE-2016-9573 [MEDIUM] CVE-2016-9573 CVE-2016-9572 openjpeg2: various flaws [epel-6]
CVE-2016-9573 CVE-2016-9572 openjpeg2: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
openjpeg2-2.3.0-6.el6 has been submitted as an update to Fe
Bugzilla
CVE-2016-9572 openjpeg: NULL pointer dereference in input decoding
bugzilla·2016-12-08·CVSS 5.9
CVE-2016-9572 [MEDIUM] CVE-2016-9572 openjpeg: NULL pointer dereference in input decoding
CVE-2016-9572 openjpeg: NULL pointer dereference in input decoding
A NULL pointer dereference flaw was found in the way openjpeg decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
Upstream bug:
https://github.com/uclouvain/openjpeg/issues/863
Upstream patch:
https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d
Note that the above patch fixes two issues: CVE-2016-9573 as well as CVE-2016-9572.
Discussion:
Acknowledgments:
Name: Liu Bingchang (IIE)
---
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1402721]
Created mingw-openjpeg2 tracking bugs for this issue:
Affect
Bugzilla
CVE-2016-9573 CVE-2016-9572 mingw-openjpeg: various flaws [fedora-all]
bugzilla·2016-12-08·CVSS 5.9
CVE-2016-9573 [MEDIUM] CVE-2016-9573 CVE-2016-9572 mingw-openjpeg: various flaws [fedora-all]
CVE-2016-9573 CVE-2016-9572 mingw-openjpeg: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2016-9573 openjpeg: heap out-of-bounds read due to insufficient check in imagetopnm()
bugzilla·2016-12-08·CVSS 5.9
CVE-2016-9573 [MEDIUM] CVE-2016-9573 openjpeg: heap out-of-bounds read due to insufficient check in imagetopnm()
CVE-2016-9573 openjpeg: heap out-of-bounds read due to insufficient check in imagetopnm()
A heap buffer overflow flaw was found in the way openjpeg decompressed certain input images. Due to an insufficient check in the imagetopnm() function, an application using openjpeg to process image data could crash when processing a crafted image.
Upstream bug:
https://github.com/uclouvain/openjpeg/issues/862
Upstream patch:
https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d
Note that the above patch fixes two issues: CVE-2016-9573 as well as CVE-2016-9572.
Discussion:
Acknowledgments:
Name: Liu Bingchang (IIE)
---
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1402721]
Created mingw-openjpeg2 tracking bugs for this issue:
Bugzilla
CVE-2016-9573 CVE-2016-9572 mingw-openjpeg2: various flaws [fedora-all]
bugzilla·2016-12-08·CVSS 5.9
CVE-2016-9573 [MEDIUM] CVE-2016-9573 CVE-2016-9572 mingw-openjpeg2: various flaws [fedora-all]
CVE-2016-9573 CVE-2016-9572 mingw-openjpeg2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2016-9573 CVE-2016-9572 openjpeg: various flaws [fedora-all]
bugzilla·2016-12-08·CVSS 5.9
CVE-2016-9573 [MEDIUM] CVE-2016-9573 CVE-2016-9572 openjpeg: various flaws [fedora-all]
CVE-2016-9573 CVE-2016-9572 openjpeg: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2016-9573 CVE-2016-9572 openjpeg2: various flaws [fedora-all]
bugzilla·2016-12-08·CVSS 5.9
CVE-2016-9573 [MEDIUM] CVE-2016-9573 CVE-2016-9572 openjpeg2: various flaws [fedora-all]
CVE-2016-9573 CVE-2016-9572 openjpeg2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
http://www.securityfocus.com/bid/109233https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9572https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0dhttps://github.com/uclouvain/openjpeg/issues/863https://security.gentoo.org/glsa/201710-26https://www.debian.org/security/2017/dsa-3768https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.securityfocus.com/bid/109233https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9572https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0dhttps://github.com/uclouvain/openjpeg/issues/863https://security.gentoo.org/glsa/201710-26https://www.debian.org/security/2017/dsa-3768https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-08-01
Published