REDHAT-BUG-1317826: Double Free
Double free or heap corruption vulnerability was found in opjfree function triggered by specially crafted JPEG2000 image file was found in openjpeg 2016.03.14.
CVE request (contains reproducer):
http://seclists.org/oss-sec/2016/q1/631
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1317826?
The severity of REDHAT-BUG-1317826 is high due to the potential for double free or heap corruption which can lead to arbitrary code execution.
How do I fix REDHAT-BUG-1317826?
To fix REDHAT-BUG-1317826, it is recommended to update to the latest version of OpenJPEG where the vulnerability has been patched.
What causes the vulnerability REDHAT-BUG-1317826?
The vulnerability REDHAT-BUG-1317826 is caused by a double free or heap corruption triggered by processing specially crafted JPEG2000 image files.
Which software versions are affected by REDHAT-BUG-1317826?
The vulnerability REDHAT-BUG-1317826 affects all versions of OpenJPEG prior to the fix implemented for this specific issue.
Is there a known exploit for REDHAT-BUG-1317826?
Yes, there is a known exploit for REDHAT-BUG-1317826 that demonstrates the triggering of the vulnerability using specially crafted JPEG2000 files.