SB2018080136 - NULL pointer dereference in OpenJPEG
Published: August 1, 2018 Updated: December 29, 2020
Security Bulletin ID
SB2018080136
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2016-9572)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image. A remote attacker can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- http://www.securityfocus.com/bid/109233
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9572
- https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d
- https://github.com/uclouvain/openjpeg/issues/863
- https://security.gentoo.org/glsa/201710-26
- https://www.debian.org/security/2017/dsa-3768
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html