First published: Wed Sep 21 2016(Updated: )
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJPEG | <2.2.0 | |
Debian Linux | =8.0 | |
Red Hat Fedora | =23 | |
Red Hat Fedora | =24 | |
Red Hat Fedora | =25 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.3 | |
Red Hat Enterprise Linux Server EUS | =7.4 | |
Red Hat Enterprise Linux Server EUS | =7.5 | |
Red Hat Enterprise Linux Server EUS | =7.6 | |
Red Hat Enterprise Linux Server EUS | =7.7 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7163 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2016-7163, update OpenJPEG to version 2.2.0 or later, or apply relevant patches provided by your operating system vendor.
CVE-2016-7163 allows remote attackers to execute arbitrary code through a crafted JP2 file.
CVE-2016-7163 affects OpenJPEG versions earlier than 2.2.0 and several versions of Debian and Fedora systems.
Yes, CVE-2016-7163 can result in data loss or corruption due to unauthorized arbitrary code execution.