Bug 971615 (CVE-2016-3182) - VUL-0: CVE-2016-3182: openjpeg2: Heap corruption in opj_free function
Summary: VUL-0: CVE-2016-3182: openjpeg2: Heap corruption in opj_free function
Status: RESOLVED FIXED
Alias: CVE-2016-3182
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other All
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/163489/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-03-17 13:55 UTC by Victor Pereira
Modified: 2022-04-01 07:26 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2016-03-17 13:55:32 UTC
rh#1317826

Double free or heap corruption vulnerability was found in opj_free function triggered by specially crafted JPEG2000 image file was found in openjpeg 2016.03.14.


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1317826
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-3182
http://seclists.org/oss-sec/2016/q1/667
Comment 1 Swamp Workflow Management 2016-03-17 23:00:44 UTC
bugbot adjusting priority
Comment 2 Asterios Dramis 2017-01-31 21:00:54 UTC
Sorry for taking so long to reply...

This issue does not affect openjpeg but openjpeg2 (see also rh#1317826). Reassigning to default since I do not maintain openjpeg2.
Comment 3 Michael Vetter 2019-03-29 10:09:55 UTC
Upstream bug: https://github.com/uclouvain/openjpeg/issues/726
Upstream fix: https://github.com/uclouvain/openjpeg/commit/15f081c89650dccee4aa4ae66f614c3fdb268767.patch

I would propose to upgrade openjpeg to 2.3.0 in leap 42.3 to fix all the issues at once.
Comment 4 Michael Vetter 2019-03-29 10:13:17 UTC
Sorry, above comment was intended for another bug.
For this one upstream issue is: https://github.com/uclouvain/openjpeg/issues/725

Still an update to 2.3.0 would solve it.
Comment 6 Hans Petter Jansson 2022-04-01 02:06:19 UTC
Origin of the issue seems to be the same as for bug 971618 (CVE-2016-3181). I addressed it there. Suggest we close this, but up to maint-coord.
Comment 7 Marcus Meissner 2022-04-01 07:26:44 UTC
closing.