Intrusion Prevention

OpenJPEG.JPEG2.Image.Processing.MCC.Memory.Corruption

Description

This indicates an attack attempt to exploit a Memory Corruption vulnerability in OpenJPEG.
The vulnerability is due to an error in checking boundaries when the vulnerable application handles a maliciously crafted JPEG2000 file. A remote attacker may be able to exploit this to execute arbitrary code under the context of the user via a crafted JPEG file.

Affected Products

OpenJPEG OpenJPEG prior to 2.1.2

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the latest update from the vendor.
http://www.openjpeg.org/2016/09/28/OpenJPEG-2.1.2-released

CVE References

CVE-2016-8332