CVE-2016-9114
Publication date 30 October 2016
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
Status
Package | Ubuntu Release | Status |
---|---|---|
ghostscript | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
openjpeg | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Ignored changes too intrusive | |
14.04 LTS trusty | Ignored changes too intrusive | |
openjpeg2 | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Vulnerable
|
|
14.04 LTS trusty | Not in release | |
Notes
ccdm94
According to comments in issue 863 (related to CVE-2016-9572), https://github.com/uclouvain/openjpeg/issues/863#issuecomment-258071962 to be more specific, and the changes in commit 2fa0fc61f2d, which fixes 862, it seems like this issue might be fixed by commit 2fa0fc61f2d (this commit, however, seems to be incomplete, and this is fixed by additionally adding 784d4d47e97).
eslerm
in addition to 2fa0fc6 and 784d4d4, c22cbd8 and 00f4568 was applied to this set of CVEs note that 00f4568 is part of 0394f8d
Patch details
Package | Patch details |
---|---|
openjpeg | |
openjpeg2 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |