4.3
CVSSv2

CVE-2016-10504

Published: 30/08/2017 Updated: 09/09/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG prior to 2.2.0 allows remote malicious users to cause a denial of service (application crash) via a crafted bmp file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uclouvain openjpeg

Vendor Advisories

Debian Bug report logs - #874113 openjpeg2: CVE-2016-10504: Heap-based buffer over-write in in opj_mqc_byteout function of mqcc Package: src:openjpeg2; Maintainer for src:openjpeg2 is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Da ...
Debian Bug report logs - #874430 openjpeg2: CVE-2017-14151: heap-based buffer overflow in opj_mqc_flush Package: src:openjpeg2; Maintainer for src:openjpeg2 is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 6 Sep 2017 04:5 ...
Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of service or the execution of arbitrary code if a malformed JPEG 2000 file is processed For the oldstable distribution (jessie), these problems have been fixed in version 210-2+deb8u3 For the stable distribution (stretch), these pr ...
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqcc in OpenJPEG before 220 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file ...

Exploits

DESCRIPTION An Out-of-Bounds Write issue can be occurred in function opj_mqc_byteout of mqcc during executing opj_compress This issue was caused by a malformed BMP file CREDIT This vulnerability was discovered by Ke Liu of Tencent's Xuanwu LAB TESTED VERSION Master version of OpenJPEG (805972f, 2016/09/12) EXCEPTION LOG ==119535==ERROR: ...