Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2016-8332: OpenJPEG JPEG2000 mcc record Code Execution Vulnerability #852

Closed
MikhailKasimov opened this issue Oct 1, 2016 · 4 comments

Comments

@MikhailKasimov
Copy link

CVE-2016-8332: OpenJPEG JPEG2000 mcc record Code Execution Vulnerability

[1] http://blog.talosintel.com/2016/09/vulnerability-spotlight-jpeg2000.html
[2] http://www.talosintelligence.com/reports/TALOS-2016-0193/

Although tested version is 2.1.1, please, check the latest released 2.1.2.

If this report is duplicate, please,close it. Thanks!

@detonin
Copy link
Contributor

detonin commented Oct 3, 2016

Thanks. This has been fixed in v2.1.2 (#820) and a non-regression test has been added to the test suite (issue820.jp2).

@detonin detonin closed this as completed Oct 3, 2016
@attritionorg
Copy link

I emailed the TALOS team, but wondering if anyone else has input on this. On the surface, this appears that it may be the same issue as #810?

@detonin
Copy link
Contributor

detonin commented Oct 4, 2016

@attritionorg duplicates both #810 and #820

@attritionorg
Copy link

Excellent, appreciate the clarification and cross-references @detonin

@detonin detonin added the bug label Aug 3, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants