Buffer overflow in OpenJPEG - CVE-2018-16375

 

Buffer overflow in OpenJPEG - CVE-2018-16375

Published: September 3, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36741
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16375
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow.


Affected software

OpenJPEG
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
SUSE Linux Enterprise Module for Packagehub Subpackages
libopenjp2-7
libopenjp2-7-debuginfo
openjpeg2-debuginfo
openjpeg2-debugsource
openjpeg2
openjpeg2-devel
libopenjp2-7-32bit
libopenjp2-7-32bit-debuginfo

How to mitigate CVE-2018-16375

Install update from vendor's website.

libopenjp2-7 - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
libopenjp2-7-debuginfo - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
openjpeg2-debuginfo - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
openjpeg2-debugsource - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
openjpeg2 - update to 2.3.0-150000.3.5.1
openjpeg2-devel - update to 2.3.0-150000.3.5.1
libopenjp2-7-32bit - update to 2.3.0-150000.3.5.1
libopenjp2-7-32bit-debuginfo - update to 2.3.0-150000.3.5.1
openjpeg2 - update to 2.3.1-1.el7

External References

Related Security Bulletins