CVE-2016-9112: Divide by Zero
Floating Point Exception (aka FPE or divide by zero) in opjpinextcprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2016-9112?
CVE-2016-9112 is a vulnerability known as Floating Point Exception (FPE or divide by zero) in the opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
How severe is CVE-2016-9112?
CVE-2016-9112 has a severity rating of 7.5, which is considered high.
Which software versions are affected by CVE-2016-9112?
The affected software versions include OpenJPEG 2.1.2, openjpeg 2.2.0, openjpeg 1:1.5.2-3.1ubuntu0.1~, openjpeg2 2.1.2-1, and openjpeg2 2.1.2-1.1+.
How do I fix CVE-2016-9112?
To fix CVE-2016-9112, update to OpenJPEG version 2.2.0 or higher, or apply the recommended remedies for the affected software versions.
Where can I find more information about CVE-2016-9112?
You can find more information about CVE-2016-9112 at the following references: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9112, https://github.com/Young-X/pocs/tree/master/OpenJPEG_POC, https://ubuntu.com/security/notices/USN-4497-1.