CVE-2017-14152
published 2017-09-05CVE-2017-14152: A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
5.15%
91.5th percentile
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjpeg2 | < openjpeg2 2.3.0-1 (bookworm) | openjpeg2 2.3.0-1 (bookworm) |
| debian | openjpeg2 | — | — |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-1 | 2.3.0-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-1 | 2.3.0-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-1 | 2.3.0-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-1 | 2.3.0-1 |
| uclouvain | openjpeg | < 2.3.0 | 2.3.0 |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r2 | 2.2.0-r2 |
| uclouvain | openjpeg | >= 0 < 2.2.0-r0 | 2.2.0-r0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg: Heap-based buffer overflow in opj_write_bytes_LE in cio.c
vendor_redhat·2017-08-20·CVSS 8.8
CVE-2017-14152 [HIGH] CWE-122 openjpeg: Heap-based buffer overflow in opj_write_bytes_LE in cio.c
openjpeg: Heap-based buffer overflow in opj_write_bytes_LE in cio.c
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution.
Package: openjpeg (Red Hat Enterprise Linux 6) - Will not fix
Package: openjpeg (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
openjpeg2: Heap-based buffer overflow in opj_write_bytes_LE
vendor_redhat·2017-08-16·CVSS 8.8
CVE-2017-14164 [HIGH] CWE-122 openjpeg2: Heap-based buffer overflow in opj_write_bytes_LE
openjpeg2: Heap-based buffer overflow in opj_write_bytes_LE
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.
Package: openjpeg (Red Hat Enterprise Linux 6) - Will not fix
Package: openjpeg (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-14152: openjpeg2 - A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/op...
vendor_debian·2017·CVSS 8.8
CVE-2017-14152 [HIGH] CVE-2017-14152: openjpeg2 - A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/op...
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution.
Scope: local
bookworm: resolved (fixed in 2.3.0-1)
bullseye: resolved (fixed in 2.3.0-1)
forky: resolved (fixed in 2.3.0-1)
sid: resolved (fixed in 2.3.0-1)
trixie: resolved (fixed in 2.3.0-1)
Debian
CVE-2017-14164: openjpeg2 - A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c...
vendor_debian·2017·CVSS 8.8
CVE-2017-14164 [HIGH] CVE-2017-14164: openjpeg2 - A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c...
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-jr34-w4rh-v3j8: A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k
ghsa_unreviewed·2022-05-13
CVE-2017-14152 [HIGH] CWE-787 GHSA-jr34-w4rh-v3j8: A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution.
GHSA
GHSA-v5g9-wqg7-v2q8: A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2017-14164 [HIGH] CWE-119 GHSA-v5g9-wqg7-v2q8: A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.
OSV
CVE-2017-14164: A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k
osv·2017-09-06·CVSS 8.8
CVE-2017-14164 [HIGH] CVE-2017-14164: A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.
OSV
CVE-2017-14152: A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k
osv·2017-09-05·CVSS 8.8
CVE-2017-14152 [HIGH] CVE-2017-14152: A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k
A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14164 openjpeg2: Heap-based buffer overflow in opj_write_bytes_LE
bugzilla·2017-09-08·CVSS 8.8
CVE-2017-14164 [HIGH] CVE-2017-14164 openjpeg2: Heap-based buffer overflow in opj_write_bytes_LE
CVE-2017-14164 openjpeg2: Heap-based buffer overflow in opj_write_bytes_LE
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.
Upstream issue:
https://github.com/uclouvain/openjpeg/issues/991
Upstream patch:
https://github.com/uclouvain/openjpeg/commit/dcac91b8c72f743bda7dbfa9032356bc8110098a
Discussion:
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1487773]
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedor
Bugzilla
CVE-2017-14151 CVE-2017-14152 openjpeg2: various flaws [fedora-all]
bugzilla·2017-08-31·CVSS 8.8
CVE-2017-14151 [HIGH] CVE-2017-14151 CVE-2017-14152 openjpeg2: various flaws [fedora-all]
CVE-2017-14151 CVE-2017-14152 openjpeg2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2017-14151 CVE-2017-14152 openjpeg: various flaws [fedora-all]
bugzilla·2017-08-31·CVSS 8.8
CVE-2017-14151 [HIGH] CVE-2017-14151 CVE-2017-14152 openjpeg: various flaws [fedora-all]
CVE-2017-14151 CVE-2017-14152 openjpeg: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2017-14151 CVE-2017-14152 openjpeg2: various flaws [epel-all]
bugzilla·2017-08-31·CVSS 8.8
CVE-2017-14151 [HIGH] CVE-2017-14151 CVE-2017-14152 openjpeg2: various flaws [epel-all]
CVE-2017-14151 CVE-2017-14152 openjpeg2: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPE
Bugzilla
CVE-2017-14152 openjpeg: Heap-based buffer overflow in opj_write_bytes_LE in cio.c
bugzilla·2017-08-31·CVSS 8.8
CVE-2017-14152 [HIGH] CVE-2017-14152 openjpeg: Heap-based buffer overflow in opj_write_bytes_LE in cio.c
CVE-2017-14152 openjpeg: Heap-based buffer overflow in opj_write_bytes_LE in cio.c
Heap-based buffer overflow vulnerability in the opj_write_bytes_LE function in cio.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.
Upstream bug:
https://github.com/uclouvain/openjpeg/issues/985
https://github.com/uclouvain/openjpeg/issues/986
Upstream patch:
https://github.com/uclouvain/openjpeg/commit/4241ae6fbbf1de9658764a80944dc8108f2b4154
References:
https://bugs.mageia.org/show_bug.cgi?id=21572
https://blogs.gentoo.org/ago/2017/08/16/openjpeg-heap-based-buffer-overflow-in-opj_write_bytes_le-cio-c/
Discussion:
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1487392]
Created mingw-openjpeg
Bugzilla
CVE-2017-14151 CVE-2017-14152 mingw-openjpeg2: various flaws [fedora-all]
bugzilla·2017-08-31·CVSS 8.8
CVE-2017-14151 [HIGH] CVE-2017-14151 CVE-2017-14152 mingw-openjpeg2: various flaws [fedora-all]
CVE-2017-14151 CVE-2017-14152 mingw-openjpeg2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2017-14151 CVE-2017-14152 mingw-openjpeg: various flaws [fedora-all]
bugzilla·2017-08-31·CVSS 8.8
CVE-2017-14151 [HIGH] CVE-2017-14151 CVE-2017-14152 mingw-openjpeg: various flaws [fedora-all]
CVE-2017-14151 CVE-2017-14152 mingw-openjpeg: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
arXiv
ORCAS: Obfuscation-Resilient Binary Code Similarity Analysis using Dominance Enhanced Semantic Graph
arxiv_fulltext·2025-08-30
ORCAS: Obfuscation-Resilient Binary Code Similarity Analysis using Dominance Enhanced Semantic Graph
[ORCAS: Obfuscation-Resilient Binary Code Similarity Analysis using Dominance Enhanced Semantic Graph]
ORCAS: OObfuscation-RResilient Binary CCode Similarity AAnalysis
%
using Dominance Enhanced SSemantic Graph
Yufeng Wang
[email protected]
0009-0000-2005-2172
College of Computer Science \ Software Engineering, \ University
Shenzhen
Guangdong
China
Yuhong Feng
Corresponding author.
[email protected]
0000-0002-7691-5587
College of Computer Science \ Software Engineering, \ University
Shenzhen
Guangdong
China
518060
Yixuan Cao
[email protected]
0009-0006-6241-4251
College of Computer Science \ Software Engineering, \ University
Shenzhen
Guangdong
China
Haoran Li
[email protected]
0009-0007-6789-5573
College of Computer Science \ Software Engine
http://www.debian.org/security/2017/dsa-4013https://blogs.gentoo.org/ago/2017/08/16/openjpeg-heap-based-buffer-overflow-in-opj_write_bytes_le-cio-c/https://github.com/uclouvain/openjpeg/commit/4241ae6fbbf1de9658764a80944dc8108f2b4154https://github.com/uclouvain/openjpeg/issues/985http://www.debian.org/security/2017/dsa-4013https://blogs.gentoo.org/ago/2017/08/16/openjpeg-heap-based-buffer-overflow-in-opj_write_bytes_le-cio-c/https://github.com/uclouvain/openjpeg/commit/4241ae6fbbf1de9658764a80944dc8108f2b4154https://github.com/uclouvain/openjpeg/issues/985
2017-09-05
Published