CVE-2016-9675

openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2017-0559.html Patch Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0838.html Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/11/29/7 Mailing List Third Party Advisory
http://www.securityfocus.com/bid/94589 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-12-22 21:59

Updated : 2024-02-04 19:11


NVD link : CVE-2016-9675

Mitre link : CVE-2016-9675

CVE.ORG link : CVE-2016-9675


JSON object : View

Products Affected

redhat

  • enterprise_linux_for_power_big_endian
  • enterprise_linux_for_ibm_z_systems
  • enterprise_linux
  • enterprise_linux_for_scientific_computing

uclouvain

  • openjpeg
CWE
CWE-787

Out-of-bounds Write