CVE-2016-9572: Null Pointer Dereference
Published Aug 1, 2018
·Updated
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
Affected Software
3 affected componentsFixes available
debian/openjpeg2
2.3.0-2+deb10u22.4.0-32.5.0-2
uclouvain openjpeg=2.1.2
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Aug 1, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2016-9572?
CVE-2016-9572 is a vulnerability in openjpeg 2.1.2 that could cause an application to crash when processing a crafted image.
2
What is the severity of CVE-2016-9572?
The severity of CVE-2016-9572 is medium, with a severity value of 6.5.
3
How does CVE-2016-9572 affect openjpeg?
CVE-2016-9572 affects openjpeg version 2.1.2.
4
How can I fix CVE-2016-9572?
To fix CVE-2016-9572, update openjpeg to version 2.3.0-2+deb10u2, 2.4.0-3, or 2.5.0-2.
5
Where can I find more information about CVE-2016-9572?
For more information about CVE-2016-9572, you can refer to the following sources: [1] [2] [3].