Back to Database
Status published
Medium
CVE-2016-9573
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in...
Vulnerability Description
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-9573
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/uclouvain/openjpeg/issues/862
- https://security.gentoo.org/glsa/201710-26
- http://www.securityfocus.com/bid/97073
- https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d
- http://rhn.redhat.com/errata/RHSA-2017-0838.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9573
- https://www.debian.org/security/2017/dsa-3768
More from The OpenJPEG Project
View All →Affected Vendor
The OpenJPEG Project
View all reports →Affected Software
openjpeg
Vulnerable Versions:
2.1.2
Timeline
Official Publish:
August 1st, 2018
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H