Input validation error in Fedora - CVE-2016-4797
Published: February 3, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU39743
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4797
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (application crash) via a crafted jp2 file.
Affected software
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
libopenjp2-7
libopenjp2-7-debuginfo
openjpeg2-debuginfo
openjpeg2-debugsource
openjpeg2
mingw-openjpeg2
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
libopenjp2-7
libopenjp2-7-debuginfo
openjpeg2-debuginfo
openjpeg2-debugsource
openjpeg2
mingw-openjpeg2
How to mitigate CVE-2016-4797
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
libopenjp2-7 - update to 2.1.0-4.15.1
libopenjp2-7-debuginfo - update to 2.1.0-4.15.1
openjpeg2-debuginfo - update to 2.1.0-4.15.1
openjpeg2-debugsource - update to 2.1.0-4.15.1
openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24
mingw-openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24
libopenjp2-7-debuginfo - update to 2.1.0-4.15.1
openjpeg2-debuginfo - update to 2.1.0-4.15.1
openjpeg2-debugsource - update to 2.1.0-4.15.1
openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24
mingw-openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24
External References
- http://www.openwall.com/lists/oss-security/2016/05/13/2
- https://bugzilla.redhat.com/show_bug.cgi?id=1335483
- https://github.com/uclouvain/openjpeg/commit/8f9cc62b3f9a1da9712329ddcedb9750d585505c
- https://github.com/uclouvain/openjpeg/issues/733
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5FFMOZOF2EI6N2CR23EQ5EATWLQKBMHW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BJM23YERMEC6LCTWBUH7LZURGSLZDFDH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFRD35RIPRCGZA5DKAKHZ62LMP2A5UT7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPMDEUIMHTLKMHELDL4F4HZ7X4Y34JEB/
- https://www.oracle.com/security-alerts/cpujul2020.html