rpm package
suse/openjpeg2&distro=SUSE Linux Enterprise Server 12 SP2
pkg:rpm/suse/openjpeg2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2
Vulnerabilities (20)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2016-9580 | Low | 3.3 | < 2.1.0-3.1 | 2.1.0-3.1 | Aug 1, 2018 | An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow. | |
| CVE-2016-9572 | Med | 5.9 | < 2.1.0-3.1 | 2.1.0-3.1 | Aug 1, 2018 | A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image. | |
| CVE-2016-9581 | Low | 3.3 | < 2.1.0-3.1 | 2.1.0-3.1 | Aug 1, 2018 | An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2. | |
| CVE-2016-9573 | Med | 6.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Aug 1, 2018 | An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap. | |
| CVE-2017-14164 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Sep 6, 2017 | A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possib | |
| CVE-2017-14041 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution. | |
| CVE-2017-14040 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact. | |
| CVE-2017-14039 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact. | |
| CVE-2016-10507 | Med | 6.5 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file. | |
| CVE-2016-9118 | Med | 5.3 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 30, 2016 | Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2. | |
| CVE-2016-9117 | Med | 6.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 30, 2016 | NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file. | |
| CVE-2016-9116 | Med | 6.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 30, 2016 | NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file. | |
| CVE-2016-9115 | Med | 6.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 30, 2016 | Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file. | |
| CVE-2016-9114 | Hig | 7.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 30, 2016 | There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service. | |
| CVE-2016-9113 | Hig | 7.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 30, 2016 | There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service. | |
| CVE-2016-9112 | Hig | 7.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 29, 2016 | Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2. | |
| CVE-2016-8332 | Hig | 7.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 28, 2016 | A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an out | |
| CVE-2016-7445 | Hig | 7.5 | < 2.1.0-3.1 | 2.1.0-3.1 | Oct 3, 2016 | convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s. | |
| CVE-2016-7163 | Hig | 7.8 | < 2.1.0-4.3.2 | 2.1.0-4.3.2 | Sep 21, 2016 | Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. | |
| CVE-2015-8871 | Cri | 9.8 | < 2.1.0-4.3.2 | 2.1.0-4.3.2 | Sep 21, 2016 | Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors. |
- affected < 2.1.0-3.1fixed 2.1.0-3.1
An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possib
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
- affected < 2.1.0-3.1fixed 2.1.0-3.1
A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an out
- affected < 2.1.0-3.1fixed 2.1.0-3.1
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
- affected < 2.1.0-4.3.2fixed 2.1.0-4.3.2
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
- affected < 2.1.0-4.3.2fixed 2.1.0-4.3.2
Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.