CVE-2016-9580Heap-based Buffer Overflow in Openjpeg Project Openjpeg2

Severity
8.8HIGHNVD
CNA3.3
EPSS
0.4%
top 40.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 13

Description

An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xhm3-jc6v-q54x: An integer overflow vulnerability was found in tiftoimage function in openjpeg 22022-05-13
CVEList
CVE-2016-9580: An integer overflow vulnerability was found in tiftoimage function in openjpeg 22018-08-01
OSV
CVE-2016-9580: An integer overflow vulnerability was found in tiftoimage function in openjpeg 22018-08-01

📋Vendor Advisories

2
Red Hat
openjpeg2: Integer overflow in tiftoimage causes heap buffer overflow2016-12-07
Debian
CVE-2016-9580: openjpeg2 - An integer overflow vulnerability was found in tiftoimage function in openjpeg 2...2016

💬Community

6
Bugzilla
CVE-2016-9580 CVE-2016-9581 openjpeg: various flaws [fedora-all]2016-12-15
Bugzilla
CVE-2016-9580 CVE-2016-9581 mingw-openjpeg2: various flaws [fedora-all]2016-12-15
Bugzilla
CVE-2016-9580 CVE-2016-9581 openjpeg2: various flaws [fedora-all]2016-12-15
Bugzilla
CVE-2016-9580 CVE-2016-9581 openjpeg2: various flaws [epel-all]2016-12-15
Bugzilla
CVE-2016-9580 openjpeg2: Integer overflow in tiftoimage causes heap buffer overflow2016-12-15
CVE-2016-9580 — Heap-based Buffer Overflow | cvebase