CVE-2016-9116: Null Pointer Dereference
Published Oct 30, 2016
·Updated
NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Affected Software
1 affected component
uclouvain openjpeg=2.1.2
Event History
Oct 30, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9116?
CVE-2016-9116 is categorized as a Denial of Service vulnerability.
2
How do I fix CVE-2016-9116?
To fix CVE-2016-9116, you should upgrade OpenJPEG to version 2.1.3 or later.
3
What component is affected by CVE-2016-9116?
CVE-2016-9116 affects the imagetopnm function in convert.c of OpenJPEG version 2.1.2.
4
What type of attack is possible with CVE-2016-9116?
An attacker can exploit CVE-2016-9116 by enticing a user to open a specially crafted j2k file.
5
Is CVE-2016-9116 a remote or local vulnerability?
CVE-2016-9116 can be exploited remotely when a user interacts with a crafted file.