Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7163

Опубликовано: 06 сент. 2016
Источник: redhat
CVSS3: 4.4
CVSS2: 5.8

Описание

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

An integer overflow, leading to a heap buffer overflow, was found in OpenJPEG. An attacker could create a crafted JPEG2000 image that, when loaded by an application using openjpeg, could lead to a crash or, potentially, code execution.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1374329openjpeg: Integer overflow in opj_pi_create_decode

4.4 Medium

CVSS3

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 9 лет назад

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

CVSS3: 7.8
nvd
около 9 лет назад

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

CVSS3: 7.8
debian
около 9 лет назад

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJ ...

CVSS3: 7.8
github
больше 3 лет назад

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.

suse-cvrf
около 8 лет назад

Security update for openjpeg2

4.4 Medium

CVSS3

5.8 Medium

CVSS2