CVE-2016-10506: Divide by Zero
Division-by-zero vulnerabilities in the functions opjpinextcprl, opjpinextpcrl, and opjpinextrpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2016-10506?
CVE-2016-10506 is a division-by-zero vulnerability in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0.
What is the severity of CVE-2016-10506?
The severity of CVE-2016-10506 is medium with a severity value of 6.5.
How does CVE-2016-10506 impact openjpeg2 package on Debian?
The openjpeg2 package on Debian is affected by CVE-2016-10506, but there is no available remedy.
How does CVE-2016-10506 impact Uclouvain Openjpeg?
Uclouvain Openjpeg is affected by CVE-2016-10506 with versions up to and including 2.1.2.
How do I fix CVE-2016-10506 in the openjpeg package on Ubuntu Xenial?
To fix CVE-2016-10506 in the openjpeg package on Ubuntu Xenial, update to version 1:1.5.2-3.1ubuntu0.1~ or later.