REDHAT-BUG-1317821: Medium severity openjpeg vulnerability
Published Mar 15, 2016
·Updated
n our-of-bounds read vulnerability in sycc422torgb function triggered by specially crafted JPEG2000 image file was found in openjpeg version 2016.03.14.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q1/632
Affected Software
1 affected component
OpenJPEG OpenJPEG
Event History
Mar 15, 2016
Data Sourced
via Red Hat·10:08 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1317821?
The severity of REDHAT-BUG-1317821 is considered high due to the potential for an out-of-bounds read vulnerability.
2
How do I fix REDHAT-BUG-1317821?
To fix REDHAT-BUG-1317821, upgrade to the latest version of OpenJPEG that addresses this vulnerability.
3
What causes the vulnerability in REDHAT-BUG-1317821?
REDHAT-BUG-1317821 is caused by an out-of-bounds read vulnerability triggered by specially crafted JPEG2000 image files.
4
Which software is affected by REDHAT-BUG-1317821?
REDHAT-BUG-1317821 affects the OpenJPEG library version 2016.03.14.
5
Can I exploit REDHAT-BUG-1317821 remotely?
Yes, REDHAT-BUG-1317821 can potentially be exploited remotely through the processing of malicious JPEG2000 files.