Vulnerability Name:

CVE-2017-14152 (CCN-131534)

Assigned:2017-08-16
Published:2017-08-16
Updated:2021-02-02
Summary:A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c and opj_j2k_write_sot in lib/openjp2/j2k.c) or possibly remote code execution.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-14152

Source: DEBIAN
Type: Third Party Advisory
DSA-4013

Source: CCN
Type: agostino's blog, August 16, 2017
openjpeg: heap-based buffer overflow in opj_write_bytes_LE (cio.c)

Source: MISC
Type: Patch, Third Party Advisory, VDB Entry
https://blogs.gentoo.org/ago/2017/08/16/openjpeg-heap-based-buffer-overflow-in-opj_write_bytes_le-cio-c/

Source: XF
Type: UNKNOWN
openjpeg-cve201714152-bo(131534)

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/uclouvain/openjpeg/commit/4241ae6fbbf1de9658764a80944dc8108f2b4154

Source: CCN
Type: OpenJPEG GIT Repository
heap-based buffer overflow in opj_write_bytes_LE (cio.c) #985

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/uclouvain/openjpeg/issues/985

Vulnerable Configuration:Configuration 1:
  • cpe:/a:uclouvain:openjpeg:2.2.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:uclouvain:openjpeg:2.2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201714152
    V
    CVE-2017-14152
    2023-06-22
    oval:org.opensuse.security:def:7629
    P
    libopenjp2-7-2.3.0-150000.3.8.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:764
    P
    Security update for the Linux Kernel (Important)
    2022-09-16
    oval:org.opensuse.security:def:3044
    P
    cups-filters-1.0.58-19.5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94674
    P
    libopenjp2-7-2.3.0-150000.3.5.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:169
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:170
    P
    libopenssl-1_1-devel-1.1.1d-11.20.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:93820
    P
    (Important)
    2022-06-10
    oval:org.opensuse.security:def:459
    P
    Security update for libslirp (Important)
    2022-04-29
    oval:org.opensuse.security:def:112737
    P
    libopenjp2-7-2.4.0-1.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69751
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:106209
    P
    libopenjp2-7-2.4.0-1.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:103358
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89703
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71289
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61548
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96668
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:47533
    P
    xinetd-2.3.15-7.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47848
    P
    perl-Archive-Zip-1.34-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47895
    P
    sudo-1.8.20p2-3.7.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47152
    P
    shim-0.9-20.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46981
    P
    krb5-appl-clients-1.0.3-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48041
    P
    hardlink-1.0-6.38 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47392
    P
    libplist3-1.12-19.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47116
    P
    pam-1.1.8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48137
    P
    libkde4-32bit-4.12.0-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47690
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47441
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47817
    P
    libyaml-0-2-0.1.6-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47681
    P
    libXpm4-3.5.11-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47020
    P
    libgc1-7.2d-3.75 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46980
    P
    krb5-1.12.5-39.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47919
    P
    xalan-j2-2.7.0-264.133 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47979
    P
    crash-7.2.1-6.42 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47244
    P
    dracut-044-113.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46995
    P
    libXinerama1-1.1.3-3.54 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48106
    P
    libecpg6-10.10-1.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47606
    P
    expat-2.1.0-21.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47309
    P
    libQt5WebKit5-5.6.2-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48208
    P
    libtirpc-netconfig-1.0.1-17.13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47752
    P
    libopenjp2-7-2.1.0-4.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:100945
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1098
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71928
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62187
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:46827
    P
    python-imaging-1.1.7-21.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71059
    P
    opensc-0.17.0-1.30 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48557
    P
    libtasn1-3.7-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61259
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70946
    P
    libXdmcp-devel-1.1.2-1.23 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46691
    P
    krb5-appl-clients-1.0.3-1.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48846
    P
    lcms-1.19-17.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46706
    P
    libXrandr2-1.4.2-3.56 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48611
    P
    qemu-2.6.1-27.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48900
    P
    finch-2.12.0-3.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46692
    P
    libFLAC++6-1.3.0-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71000
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69856
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:64272
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:100533
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107199
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116757
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71594
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61853
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:67706
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49205
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66408
    P
    grub2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73191
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64359
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67606
    P
    ghostscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73073
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49151
    P
    libXt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66500
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:201714152000
    V
    CVE-2017-14152 on Ubuntu 17.10 (artful) - medium.
    2017-09-05
    oval:com.ubuntu.bionic:def:2017141520000000
    V
    CVE-2017-14152 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-09-05
    oval:com.ubuntu.bionic:def:201714152000
    V
    CVE-2017-14152 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-09-05
    oval:com.ubuntu.xenial:def:2017141520000000
    V
    CVE-2017-14152 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-05
    oval:com.ubuntu.xenial:def:201714152000
    V
    CVE-2017-14152 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-05
    BACK
    uclouvain openjpeg 2.2.0
    debian debian linux 8.0
    debian debian linux 9.0
    openjpeg openjpeg 2.2.0