OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
BID:100633
CVE-2017-14151 |Info
OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 100633 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-14151 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2017 12:00AM |
| Updated: | Sep 05 2017 12:00AM |
| Credit: | Agostino Sarubbo of Gentoo. |
| Vulnerable: |
Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 OpenJPEG OpenJPEG 2.1.2 OpenJPEG OpenJPEG 2.1.1 OpenJPEG OpenJPEG 2.1 OpenJPEG OpenJPEG 1.5 OpenJPEG OpenJPEG 2.0.0 OpenJPEG OpenJPEG 1.5.2 OpenJPEG OpenJPEG 1.5.1 OpenJPEG OpenJPEG 1.5 OpenJPEG OpenJPEG 1.4 OpenJPEG OpenJPEG 1.3 OpenJPEG OpenJPEG 1.0 |
| Not Vulnerable: |
OpenJPEG OpenJPEG 2.2.0 |
Discussion
OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
OpenJPEG is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Versions prior to OpenJPEG 2.2.0 are vulnerable.
OpenJPEG is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Versions prior to OpenJPEG 2.2.0 are vulnerable.
Exploit / POC
OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenJPEG 'mqc.c' Remote Heap Based Buffer Overflow Vulnerability
References:
References:
- OpenJPEG Homepage (OpenJPEG)
- Bug 1487390 - (CVE-2017-14151) CVE-2017-14151 openjpeg: Heap-based buffer overfl (Redhat)
- CVE-2017-14151 (Redhat)
- Encoder: grow buffer size in opj_tcd_code_block_enc_allocate_data() t�?� (Github)
- heap-base buffer overflow in opj_mqc_flush (mqc.c) #982 (Github)
- openjpeg: heap-based buffer overflow in opj_mqc_flush (mqc.c) (Gentoo)
- poc/00314-openjpeg-heapoverflow-opj_mqc_flush (Github)