cbcvebase.
CVE-2016-9573
published 2018-08-01

CVE-2016-9573: An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could…

high8.1CVSS 3.0
AVNACLPRNUIRSUCHINAH
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianopenjpeg2< openjpeg2 2.1.2-1.1 (bookworm)openjpeg2 2.1.2-1.1 (bookworm)
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation
the_openjpeg_projectopenjpeg
the_openjpeg_projectopenjpeg2>= 0 < 2.1.2-1.12.1.2-1.1
the_openjpeg_projectopenjpeg2>= 0 < 2.1.2-1.12.1.2-1.1
the_openjpeg_projectopenjpeg2>= 0 < 2.1.2-1.12.1.2-1.1
the_openjpeg_projectopenjpeg2>= 0 < 2.1.2-1.12.1.2-1.1
uclouvainopenjpeg

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv8.1HIGH