NULL pointer dereference in OpenJPEG and Debian Linux - CVE-2016-9572
Published: August 1, 2018 / Updated: December 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image. A remote attacker can perform a denial of service (DoS) attack.
Affected software
SUSE Package Hub for SUSE Linux Enterprise
Debian Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
Oracle Database Server
openjpeg2
mingw-openjpeg2
How to mitigate CVE-2016-9572
mingw-openjpeg2 - addressed in versions 2.1.2-2.fc23, 2.1.2-2.fc24, 2.1.2-2.fc25, 2.1.2-3.fc23, 2.1.2-3.fc24, 2.1.2-3.fc25
External References
- http://www.securityfocus.com/bid/109233
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9572
- https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d
- https://github.com/uclouvain/openjpeg/issues/863
- https://security.gentoo.org/glsa/201710-26
- https://www.debian.org/security/2017/dsa-3768
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Related Security Bulletins
- NULL pointer dereference in OpenJPEG
- OpenSUSE Linux update for openjpeg2
- OpenSUSE Linux update for openjpeg2
- OpenSUSE Linux update for openjpeg2
- SUSE Linux update for openjpeg2
- Slackware Linux update for openjpeg
- Fedora 23 update for openjpeg2
- Fedora 25 update for openjpeg2
- Fedora 24 update for openjpeg2
- Fedora 24 update for mingw-openjpeg2
- Fedora 25 update for mingw-openjpeg2
- Fedora 23 update for mingw-openjpeg2
- Fedora 23 update for openjpeg2
- Fedora 23 update for mingw-openjpeg2
- Fedora 25 update for mingw-openjpeg2
- Fedora 24 update for mingw-openjpeg2
- Multiple vulnerabilities in Oracle Database Server