Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2016.0426
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2016-0426)
Summary:The remote host is missing an update for the 'openjpeg2' package(s) announced via the MGASA-2016-0426 advisory.
Description:Summary:
The remote host is missing an update for the 'openjpeg2' package(s) announced via the MGASA-2016-0426 advisory.

Vulnerability Insight:
A NULL pointer dereference flaw was found in the way openjpeg decoded
certain input images. Due to a logic error in the code responsible for
decoding the input image, an application using openjpeg to process image
data could crash when processing a crafted image (CVE-2016-9572).

A heap buffer overflow flaw was found in the way openjpeg decompressed
certain input images. Due to an insufficient check in the imagetopnm()
function, an application using openjpeg to process image data could
crash when processing a crafted image (CVE-2016-9573).

An integer overflow vulnerability was found in tiftoimage function
resulting into heap buffer overflow (CVE-2016-9580).

An infinite loop vulnerability in tiftoimage that results into heap
buffer overflow in convert_32s_C1P1 was found (CVE-2016-9581)

Affected Software/OS:
'openjpeg2' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-9572
109233
http://www.securityfocus.com/bid/109233
DSA-3768
https://www.debian.org/security/2017/dsa-3768
GLSA-201710-26
https://security.gentoo.org/glsa/201710-26
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9572
https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d
https://github.com/uclouvain/openjpeg/issues/863
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-9573
97073
http://www.securityfocus.com/bid/97073
RHSA-2017:0838
http://rhn.redhat.com/errata/RHSA-2017-0838.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9573
https://github.com/uclouvain/openjpeg/issues/862
Common Vulnerability Exposure (CVE) ID: CVE-2016-9580
94822
http://www.securityfocus.com/bid/94822
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9580
https://github.com/szukw000/openjpeg/commit/cadff5fb6e73398de26a92e96d3d7cac893af255
https://github.com/uclouvain/openjpeg/issues/871
Common Vulnerability Exposure (CVE) ID: CVE-2016-9581
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9581
https://github.com/uclouvain/openjpeg/issues/872
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.