First published: Wed Sep 21 2016(Updated: )
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJPEG | <2.2.0 | |
Debian | =8.0 | |
Fedora | =23 | |
Fedora | =24 | |
Fedora | =25 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =7.3 | |
redhat enterprise Linux eus | =7.4 | |
redhat enterprise Linux eus | =7.5 | |
redhat enterprise Linux eus | =7.6 | |
redhat enterprise Linux eus | =7.7 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.3 | |
redhat enterprise Linux server aus | =7.4 | |
redhat enterprise Linux server aus | =7.6 | |
redhat enterprise Linux server aus | =7.7 | |
redhat enterprise Linux server tus | =7.3 | |
redhat enterprise Linux server tus | =7.6 | |
redhat enterprise Linux server tus | =7.7 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7163 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2016-7163, update OpenJPEG to version 2.2.0 or later, or apply relevant patches provided by your operating system vendor.
CVE-2016-7163 allows remote attackers to execute arbitrary code through a crafted JP2 file.
CVE-2016-7163 affects OpenJPEG versions earlier than 2.2.0 and several versions of Debian and Fedora systems.
Yes, CVE-2016-7163 can result in data loss or corruption due to unauthorized arbitrary code execution.