CVE-2016-9581Heap-based Buffer Overflow in Openjpeg Project Openjpeg2

Severity
8.8HIGHNVD
CNA3.3
EPSS
0.3%
top 44.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateMay 13

Description

An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qrq4-w8rp-x888: An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 22022-05-13
OSV
CVE-2016-9581: An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 22018-08-01
CVEList
CVE-2016-9581: An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 22018-08-01

📋Vendor Advisories

2
Red Hat
openjpeg2: Infinite loop in tiftoimage resulting into heap buffer overflow in convert_32s_C1P12016-12-07
Debian
CVE-2016-9581: openjpeg2 - An infinite loop vulnerability in tiftoimage that results in heap buffer overflo...2016

💬Community

6
Bugzilla
CVE-2016-9580 CVE-2016-9581 openjpeg: various flaws [fedora-all]2016-12-15
Bugzilla
CVE-2016-9580 CVE-2016-9581 mingw-openjpeg2: various flaws [fedora-all]2016-12-15
Bugzilla
CVE-2016-9580 CVE-2016-9581 openjpeg2: various flaws [fedora-all]2016-12-15
Bugzilla
CVE-2016-9580 CVE-2016-9581 openjpeg2: various flaws [epel-all]2016-12-15
Bugzilla
CVE-2016-9581 openjpeg2: Infinite loop in tiftoimage resulting into heap buffer overflow in convert_32s_C1P12016-12-15
CVE-2016-9581 — Heap-based Buffer Overflow | cvebase