CVE-2016-8332

A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an out of bound heap write resulting in heap corruption leading to arbitrary code execution. For a successful attack, the target user needs to open a malicious jpeg2000 file. The jpeg2000 image file format is mostly used for embedding images inside PDF documents and the OpenJpeg library is used by a number of popular PDF renderers making PDF documents a likely attack vector.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
talosCNA
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
uclouvainopenjpeg
2.1.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
openjpegopenjpeg
2.1.1
CNA
Debian logo
Debian Releases
Debian Product
Codename
openjpeg2
bookworm
2.5.0-2
fixed
bullseye
2.4.0-3
fixed
sid
2.5.0-2
fixed
trixie
2.5.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjpeg
precise
not-affected
trusty
not-affected
xenial
not-affected
openjpeg2
precise
dne
trusty
dne
xenial
Fixed 2.1.0-2.1ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libopenjp2-7
suse enterprise desktop 15
2.3.0-1.25
fixed
suse enterprise desktop 15 SP1
2.3.0-1.25
fixed
suse enterprise desktop 15 SP2
2.3.0-1.25
fixed
suse enterprise desktop 15 SP3
2.3.0-1.25
fixed
suse enterprise desktop 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise desktop 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise desktop 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise desktop 15 SP7
2.3.0-150000.3.18.1
fixed
suse enterprise sap 15
2.3.0-1.25
fixed
suse enterprise sap 15 SP1
2.3.0-1.25
fixed
suse enterprise sap 15 SP2
2.3.0-1.25
fixed
suse enterprise sap 15 SP3
2.3.0-1.25
fixed
suse enterprise sap 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise sap 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise sap 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise sap 15 SP7
2.3.0-150000.3.18.1
fixed
suse enterprise server 15
2.3.0-1.25
fixed
suse enterprise server 15 SP1
2.3.0-1.25
fixed
suse enterprise server 15 SP2
2.3.0-1.25
fixed
suse enterprise server 15 SP3
2.3.0-1.25
fixed
suse enterprise server 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise server 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise server 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise server 15 SP7
2.3.0-150000.3.18.1
fixed
openjpeg2
suse enterprise desktop 15
2.3.0-1.25
fixed
suse enterprise desktop 15 SP1
2.3.0-1.25
fixed
suse enterprise desktop 15 SP2
2.3.0-1.25
fixed
suse enterprise desktop 15 SP3
2.3.0-1.25
fixed
suse enterprise desktop 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise desktop 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise desktop 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise desktop 15 SP7
2.3.0-150000.3.18.1
fixed
suse enterprise sap 15
2.3.0-1.25
fixed
suse enterprise sap 15 SP1
2.3.0-1.25
fixed
suse enterprise sap 15 SP2
2.3.0-1.25
fixed
suse enterprise sap 15 SP3
2.3.0-1.25
fixed
suse enterprise sap 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise sap 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise sap 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise sap 15 SP7
2.3.0-150000.3.18.1
fixed
suse enterprise server 15
2.3.0-1.25
fixed
suse enterprise server 15 SP1
2.3.0-1.25
fixed
suse enterprise server 15 SP2
2.3.0-1.25
fixed
suse enterprise server 15 SP3
2.3.0-1.25
fixed
suse enterprise server 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise server 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise server 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise server 15 SP7
2.3.0-150000.3.18.1
fixed
openjpeg2-devel
suse enterprise desktop 15
2.3.0-1.25
fixed
suse enterprise desktop 15 SP1
2.3.0-1.25
fixed
suse enterprise desktop 15 SP2
2.3.0-1.25
fixed
suse enterprise desktop 15 SP3
2.3.0-1.25
fixed
suse enterprise desktop 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise desktop 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise desktop 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise desktop 15 SP7
2.3.0-150000.3.18.1
fixed
suse enterprise sap 15
2.3.0-1.25
fixed
suse enterprise sap 15 SP1
2.3.0-1.25
fixed
suse enterprise sap 15 SP2
2.3.0-1.25
fixed
suse enterprise sap 15 SP3
2.3.0-1.25
fixed
suse enterprise sap 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise sap 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise sap 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise sap 15 SP7
2.3.0-150000.3.18.1
fixed
suse enterprise server 15
2.3.0-1.25
fixed
suse enterprise server 15 SP1
2.3.0-1.25
fixed
suse enterprise server 15 SP2
2.3.0-1.25
fixed
suse enterprise server 15 SP3
2.3.0-1.25
fixed
suse enterprise server 15 SP4
2.3.0-150000.3.5.1
fixed
suse enterprise server 15 SP5
2.3.0-150000.3.8.1
fixed
suse enterprise server 15 SP6
2.3.0-150000.3.13.1
fixed
suse enterprise server 15 SP7
2.3.0-150000.3.18.1
fixed