First published: Sat Oct 29 2016(Updated: )
Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclouvain Openjpeg | =2.1.2 | |
debian/openjpeg2 | 2.4.0-3 2.5.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9112 is a vulnerability known as Floating Point Exception (FPE or divide by zero) in the opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
CVE-2016-9112 has a severity rating of 7.5, which is considered high.
The affected software versions include OpenJPEG 2.1.2, openjpeg 2.2.0, openjpeg 1:1.5.2-3.1ubuntu0.1~, openjpeg2 2.1.2-1, and openjpeg2 2.1.2-1.1+.
To fix CVE-2016-9112, update to OpenJPEG version 2.2.0 or higher, or apply the recommended remedies for the affected software versions.
You can find more information about CVE-2016-9112 at the following references: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9112, https://github.com/Young-X/pocs/tree/master/OpenJPEG_POC, https://ubuntu.com/security/notices/USN-4497-1.