First published: Tue Mar 15 2016(Updated: )
Double free or heap corruption vulnerability was found in opj_free function triggered by specially crafted JPEG2000 image file was found in openjpeg 2016.03.14. CVE request (contains reproducer): <a href="http://seclists.org/oss-sec/2016/q1/631">http://seclists.org/oss-sec/2016/q1/631</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
uclouvain openjpeg | <2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3182 has a severity rating of medium due to the potential for denial of service from heap corruption.
CVE-2016-3182 affects versions of OpenJPEG prior to 2.1.1.
To fix CVE-2016-3182, upgrade OpenJPEG to version 2.1.1 or later.
CVE-2016-3182 is a double free or heap corruption vulnerability triggered by specially crafted JPEG2000 image files.
Yes, CVE-2016-3182 can be exploited in real-world scenarios, potentially leading to application crashes.