OpenJPEG CVE-2017-14164 Incomplete Fix Remote Heap Based Buffer Overflow Vulnerability
BID:100677
CVE-2017-14164 |Info
OpenJPEG CVE-2017-14164 Incomplete Fix Remote Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 100677 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-14164 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2017 12:00AM |
| Updated: | Sep 06 2017 12:00AM |
| Credit: | Agostino Sarubbo of Gentoo. |
| Vulnerable: |
OpenJPEG OpenJPEG 2.2.0 |
| Not Vulnerable: | |
Discussion
OpenJPEG CVE-2017-14164 Incomplete Fix Remote Heap Based Buffer Overflow Vulnerability
OpenJPEG is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
OpenJPEG 2.2.0 is vulnerable.
OpenJPEG is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
An attacker can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.
OpenJPEG 2.2.0 is vulnerable.
Exploit / POC
OpenJPEG CVE-2017-14164 Incomplete Fix Remote Heap Based Buffer Overflow Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
OpenJPEG CVE-2017-14164 Incomplete Fix Remote Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.