CVE-2016-3183
Summary
| CVE | CVE-2016-3183 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-03 16:59:00 UTC |
| Updated | 2023-11-07 02:32:00 UTC |
| Description | The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OpenJPEG: Multiple vulnerabilities (GLSA 201612-26) — Gentoo Security | GENTOO | security.gentoo.org | Patch, Third Party Advisory, VDB Entry |
| Fix Out-Of-Bounds Read in sycc42x_to_rgb function (#745) · uclouvain/openjpeg@15f081c · GitHub | CONFIRM | github.com | Issue Tracking, Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2020 | MISC | www.oracle.com | |
| Bug 1317821 – CVE-2016-3183 openjpeg: Out-of-bounds read in sycc422_to_rgb function | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch |
| CVE-2016-3183 Out-Of-Bounds Read in sycc422_to_rgb function · Issue #726 · uclouvain/openjpeg · GitHub | CONFIRM | github.com | Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] Fedora 23 Update: openjpeg2-2.1.1-1.fc23 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| oss-security - Re: CVE request - OpenJPEG : Out-Of-Bounds Read in sycc422_to_rgb function | MLIST | www.openwall.com | Mailing List, Patch |
| [SECURITY] Fedora 24 Update: openjpeg2-2.1.1-1.fc24 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Patch, Third Party Advisory |
| [SECURITY] Fedora 24 Update: mingw-openjpeg2-2.1.1-1.fc24 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 23 Update: mingw-openjpeg2-2.1.1-1.fc23 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 24 Update: mingw-openjpeg2-2.1.1-1.fc24 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Patch, Third Party Advisory |
| [SECURITY] Fedora 23 Update: mingw-openjpeg2-2.1.1-1.fc23 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Patch, Third Party Advisory |
| [SECURITY] Fedora 24 Update: openjpeg2-2.1.1-1.fc24 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 23 Update: openjpeg2-2.1.1-1.fc23 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 751971 SUSE Enterprise Linux Security Update for openjpeg2 (SUSE-SU-2022:1129-1)