Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9573

Опубликовано: 01 авг. 2018
Источник: nvd
CVSS3: 6.5
CVSS3: 8.1
CVSS2: 5.8
EPSS Низкий

Описание

An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uclouvain:openjpeg:2.1.2:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01115
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.

CVSS3: 6.5
redhat
около 9 лет назад

An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.

CVSS3: 6.5
debian
больше 7 лет назад

An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in th ...

CVSS3: 8.1
github
больше 3 лет назад

An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.

oracle-oval
больше 8 лет назад

ELSA-2017-0838: openjpeg security update (MODERATE)

EPSS

Процентиль: 78%
0.01115
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-125
CWE-125