CVE-2016-9117: Null Pointer Dereference
Published Oct 30, 2016
·Updated
NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Affected Software
1 affected component
uclouvain openjpeg=2.1.2
Event History
Oct 30, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9117?
CVE-2016-9117 has a severity level classified as a Denial of Service (DoS).
2
What is the impact of CVE-2016-9117?
The impact of CVE-2016-9117 is a Denial of Service that can occur by opening a crafted j2k file.
3
How do I fix CVE-2016-9117?
To fix CVE-2016-9117, upgrade OpenJPEG to a version later than 2.1.2, where the vulnerability has been addressed.
4
Which versions of OpenJPEG are affected by CVE-2016-9117?
OpenJPEG version 2.1.2 is specifically affected by CVE-2016-9117.
5
How does CVE-2016-9117 occur within OpenJPEG?
CVE-2016-9117 occurs due to a NULL Pointer Access in the imagetopnm function, leading to potential crashes.