CVE-2016-4796: Buffer Overflow
A heap buffer overflow in function colorcmyktorgb in color.c.
Upstream patch:
https://github.com/uclouvain/openjpeg/commit/162f6199c0cd3ec1c6c6dc65e41b2faab92b2d91
CVE request:
http://seclists.org/oss-sec/2016/q2/327
Other sources
Heap-based buffer overflow in the colorcmyktorgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4796?
CVE-2016-4796 is classified as a high severity vulnerability due to the potential for heap buffer overflow leading to exploitation.
How do I fix CVE-2016-4796?
To mitigate CVE-2016-4796, users should update to the patched version of OpenJPEG that addresses the heap buffer overflow.
Which versions of OpenJPEG are affected by CVE-2016-4796?
CVE-2016-4796 affects OpenJPEG versions up to and including 2.1.0.
Can CVE-2016-4796 be exploited remotely?
Yes, CVE-2016-4796 can potentially be exploited remotely by attackers through crafted CMYK images.
What kind of impact does CVE-2016-4796 have on the system?
The impact of CVE-2016-4796 may include crashes, arbitrary code execution, or denial of service on affected systems.