CVE-2016-9675
published 2016-12-22CVE-2016-9675: openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.90%
77.3th percentile
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_for_scientific_computing | — | — |
| uclouvain | openjpeg | < 1.5.2 | 1.5.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg: incorrect fix for CVE-2013-6045
vendor_redhat·2016-09-26·CVSS 7.5
CVE-2016-9675 [HIGH] CWE-122 openjpeg: incorrect fix for CVE-2013-6045
openjpeg: incorrect fix for CVE-2013-6045
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
A vulnerability was found in the patch for CVE-2013-6045 for OpenJPEG. A specially crafted JPEG2000 image, when read by an application using OpenJPEG, could cause heap-based buffer overflows leading to a crash or possible code execution.
GHSA
GHSA-6xgj-8663-75f9: openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2016-9675 [HIGH] CWE-119 GHSA-6xgj-8663-75f9: openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
OSV
CVE-2016-9675: openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045
osv·2016-12-22·CVSS 7.5
CVE-2016-9675 [HIGH] CVE-2016-9675: openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9675 openjpeg: incorrect fix for CVE-2013-6045
bugzilla·2016-10-06·CVSS 7.5
CVE-2016-9675 [HIGH] CVE-2016-9675 openjpeg: incorrect fix for CVE-2013-6045
CVE-2016-9675 openjpeg: incorrect fix for CVE-2013-6045
A flaw was found in the patch for CVE-2013-6045 for openjpeg-1. A crafted
jpeg2000 image could cause heap-based buffer overflows, leading to a crash or
possible code execution when reading or converting the crafted file.
External reference:
http://seclists.org/oss-sec/2016/q3/624
See also:
https://bugzilla.redhat.com/show_bug.cgi?id=1036495#c20
https://bugs.debian.org/734238
Adjusted patch attached, but see also:
http://pkgs.fedoraproject.org/cgit/rpms/openjpeg.git/commit/?id=ecc78395d2c04b4bc4e37435c2c9c5a603f8910a
Discussion:
Created openjpeg tracking bugs for this issue:
Affects: epel-5 [bug 1382205]
---
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1382204]
---
Acknowledgments:
Name:
Bugzilla
CVE-2016-7163 openjpeg: Integer overflow in opj_pi_create_decode
bugzilla·2016-09-08·CVSS 7.8
CVE-2016-7163 [HIGH] CVE-2016-7163 openjpeg: Integer overflow in opj_pi_create_decode
CVE-2016-7163 openjpeg: Integer overflow in opj_pi_create_decode
An integer overflow in opj_pi_create_decode of pi.c was found that leads to out-of-bounds read and write in opj_pi_next_cprl of pi.c.
Upstream fix:
https://github.com/uclouvain/openjpeg/commit/c16bc057ba3f125051c9966cf1f5b68a05681de4
https://github.com/uclouvain/openjpeg/commit/ef01f18dfc6780b776d0674ed3e7415c6ef54d24
CVE assignment:
http://seclists.org/oss-sec/2016/q3/442
Discussion:
Created openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1374339]
---
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1374341]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1374340]
Affects: epel-all [bug 1374343]
---
Created mingw-openjpeg2 tracking bugs
http://rhn.redhat.com/errata/RHSA-2017-0559.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0838.htmlhttp://www.openwall.com/lists/oss-security/2016/11/29/7http://www.securityfocus.com/bid/94589http://rhn.redhat.com/errata/RHSA-2017-0559.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0838.htmlhttp://www.openwall.com/lists/oss-security/2016/11/29/7http://www.securityfocus.com/bid/94589
2016-12-22
Published