CVE-2016-4797 PUBLISHED

Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.

EPSS 0.29% · 51.7th percentile

Risk Scores

EPSS Score
0.29%
51.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSopenjpeg20, 2.1.0-2.1, 2.1.0-2.1ubuntu0.1

Timeline

References

Open in Interactive Console →