First published: Tue Mar 15 2016(Updated: )
Double free or heap corruption vulnerability was found in opj_free function triggered by specially crafted JPEG2000 image file was found in openjpeg 2016.03.14. CVE request (contains reproducer): <a href="http://seclists.org/oss-sec/2016/q1/631">http://seclists.org/oss-sec/2016/q1/631</a>
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJPEG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1317826 is high due to the potential for double free or heap corruption which can lead to arbitrary code execution.
To fix REDHAT-BUG-1317826, it is recommended to update to the latest version of OpenJPEG where the vulnerability has been patched.
The vulnerability REDHAT-BUG-1317826 is caused by a double free or heap corruption triggered by processing specially crafted JPEG2000 image files.
The vulnerability REDHAT-BUG-1317826 affects all versions of OpenJPEG prior to the fix implemented for this specific issue.
Yes, there is a known exploit for REDHAT-BUG-1317826 that demonstrates the triggering of the vulnerability using specially crafted JPEG2000 files.