OpenJPEG 'cio.c' Remote Heap Based Buffer Overflow Vulnerability
BID:100635
Info
OpenJPEG 'cio.c' Remote Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 100635 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-14152 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2017 12:00AM |
| Updated: | Aug 16 2017 12:00AM |
| Credit: | Agostino Sarubbo of Gentoo. |
| Vulnerable: |
Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 OpenJPEG OpenJPEG 2.1.2 OpenJPEG OpenJPEG 2.1.1 OpenJPEG OpenJPEG 2.1 OpenJPEG OpenJPEG 1.5 OpenJPEG OpenJPEG 2.0.0 OpenJPEG OpenJPEG 1.5.2 OpenJPEG OpenJPEG 1.5.1 OpenJPEG OpenJPEG 1.5 OpenJPEG OpenJPEG 1.4 OpenJPEG OpenJPEG 1.3 OpenJPEG OpenJPEG 1.0 |
| Not Vulnerable: |
OpenJPEG OpenJPEG 2.2.0 |
Discussion
OpenJPEG 'cio.c' Remote Heap Based Buffer Overflow Vulnerability
OpenJPEG is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Versions prior to OpenJPEG 2.2.0 are vulnerable.
OpenJPEG is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
Versions prior to OpenJPEG 2.2.0 are vulnerable.
Exploit / POC
OpenJPEG 'cio.c' Remote Heap Based Buffer Overflow Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
OpenJPEG 'cio.c' Remote Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenJPEG 'cio.c' Remote Heap Based Buffer Overflow Vulnerability
References:
References:
- [CVE-2016-10504] Out-of-Bounds Write in opj_mqc_byteout of mqc.c #835 (OpenJPEG)
- Comparing changes (OpenJPEG)
- Fix write heap buffer overflow in opj_mqc_byteout(). #835 (OpenJPEG)
- OpenJPEG Homepage (OpenJPEG)
- Bug 1487389 - (CVE-2017-14152) CVE-2017-14152 openjpeg: Heap-based buffer overfl (Redhat)
- CVE-2016-10504 openjpeg: Heap-based buffer over-write in in opj_mqc_byteout func (Red Hat)
- CVE-2017-14152 (Redhat)