First published: Wed Aug 01 2018(Updated: )
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjpeg2 | 2.3.0-2+deb10u2 2.4.0-3 2.5.0-2 | |
Uclouvain Openjpeg | =2.1.2 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9572 is a vulnerability in openjpeg 2.1.2 that could cause an application to crash when processing a crafted image.
The severity of CVE-2016-9572 is medium, with a severity value of 6.5.
CVE-2016-9572 affects openjpeg version 2.1.2.
To fix CVE-2016-9572, update openjpeg to version 2.3.0-2+deb10u2, 2.4.0-3, or 2.5.0-2.
For more information about CVE-2016-9572, you can refer to the following sources: [1] [2] [3].