First published: Wed Aug 30 2017(Updated: )
Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclouvain Openjpeg | <=2.1.2 | |
debian/openjpeg2 | <=2.4.0-3<=2.5.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10506 is a division-by-zero vulnerability in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0.
The severity of CVE-2016-10506 is medium with a severity value of 6.5.
The openjpeg2 package on Debian is affected by CVE-2016-10506, but there is no available remedy.
Uclouvain Openjpeg is affected by CVE-2016-10506 with versions up to and including 2.1.2.
To fix CVE-2016-10506 in the openjpeg package on Ubuntu Xenial, update to version 1:1.5.2-3.1ubuntu0.1~ or later.