Denial of Service Vulnerability in OpenJPEG Image Processing Software
CVE-2016-3182

5.5MEDIUM

Key Information:

Vendor

Uclouvain

Status
Vendor
CVE Published:
20 February 2020

What is CVE-2016-3182?

The color_esycc_to_rgb function within OpenJPEG's color processing library is susceptible to exploitation through specially crafted JPEG 2000 files. This vulnerability can lead to memory corruption and potentially cause denial of service, impacting the application's stability and availability. Users of OpenJPEG versions prior to 2.1.1 should implement measures to mitigate this risk.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.