Bugzilla – Bug 971618
VUL-0: CVE-2016-3181: openjpeg2: Out-of-bounds read in opj_tcd_free_tile function
Last modified: 2022-04-01 08:40:09 UTC
rh#1317822 An out-of-bounds read vulnerability in opj_tcd_free_tile function causing segmentation fault triggered by specially crafted JPEG2000 image file was found in openjpeg version 2016.03.14. References: https://bugzilla.redhat.com/show_bug.cgi?id=1317822 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-3181 http://seclists.org/oss-sec/2016/q1/666
bugbot adjusting priority
This issue does not affect openjpeg but openjpeg2 (see also rh#1317822 and rh#1317826).
Upstream bug: https://github.com/uclouvain/openjpeg/issues/724 Seems to have the same fix as for CVE-2016-3182 / bsc#971615
Not applicable to SLE-12 (too old; patched function does not exist and corresponding code in old function uses an if-else ladder that implicitly validates the parameters and errors out if none of the combinations match). Not applicable to SLE-15 (fix is already in upstream). Nothing to do for this bug. If maint-coord agree, I think we can close this.
Bug closed (see comment 5).