CVE-2016-9572 PUBLISHED

A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.

EPSS 1.77% · 82.5th percentile

Risk Scores

EPSS Score
1.77%
82.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSopenjpeg*, 0, 1:1.5.2-3.1
Ubuntu:16.04:LTSopenjpeg22.1.0-2.1, 0, 2.1.0-2.1ubuntu0.1
Ubuntu:14.04:LTSopenjpeg0, 1.3+dfsg-4.7ubuntu1, 1.3+dfsg-4.6ubuntu2

Timeline

References

Open in Interactive Console →