CVE-2016-9114: Null Pointer Dereference
Published Oct 30, 2016
·Updated
There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
Affected Software
1 affected component
uclouvain openjpeg=2.1.2
Event History
Oct 30, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9114?
CVE-2016-9114 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2016-9114?
To fix CVE-2016-9114, update OpenJPEG to version 2.1.3 or later.
3
What is the impact of CVE-2016-9114?
The impact of CVE-2016-9114 is a NULL Pointer Access causing potential Denial of Service.
4
Which versions of OpenJPEG are affected by CVE-2016-9114?
Only OpenJPEG version 2.1.2 is affected by CVE-2016-9114.
5
Is CVE-2016-9114 exploitable remotely?
CVE-2016-9114 may potentially be exploited remotely through crafted image files.