Integer overflow in OpenJPEG - CVE-2016-9580

 

Integer overflow in OpenJPEG - CVE-2016-9580

Published: August 1, 2018 / Updated: August 3, 2020


Vulnerability identifier: #VU33222
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9580
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.


Affected software

OpenJPEG
SUSE Package Hub for SUSE Linux Enterprise
openjpeg (Alpine package)
openjpeg2
mingw-openjpeg2
SUSE Linux
Slackware Linux
Fedora
Opensuse

How to mitigate CVE-2016-9580

Install update from vendor's website.

OpenJPEG - update to 2.2.0
openjpeg (Alpine package) - update to 2.1.2-r1
openjpeg2 - addressed in versions 2.1.2-3.fc23, 2.1.2-3.fc24, 2.1.2-3.fc25
mingw-openjpeg2 - addressed in versions 2.1.2-3.fc23, 2.1.2-3.fc24, 2.1.2-3.fc25

External References

Related Security Bulletins