NULL pointer dereference in OpenJPEG - CVE-2016-7445

 

NULL pointer dereference in OpenJPEG - CVE-2016-7445

Published: October 3, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32239
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7445
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via vectors involving the variable s.


Affected software

OpenJPEG
SUSE Package Hub for SUSE Linux Enterprise
Gentoo Linux
SUSE Linux
Fedora
Opensuse
openjpeg (Alpine package)
media-libs/openjpeg
openjpeg2
mingw-openjpeg2

How to mitigate CVE-2016-7445

Update to version 2.1.2.

OpenJPEG - update to 2.1.2
openjpeg (Alpine package) - update to 2.1.2-r0
media-libs/openjpeg - update to 1.5.2
openjpeg2 - addressed in versions 2.1.2-1.fc23, 2.1.2-1.fc24, 2.1.2-1.fc25
mingw-openjpeg2 - addressed in versions 2.1.2-1.fc23, 2.1.2-1.fc24, 2.1.2-1.fc25

External References

Related Security Bulletins