CVE-2016-9573: Debian Linux
High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.
Affected products
- Debian Debian Linux: version 8.0 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only
- Red Hat Enterprise Linux Server Eus: version 7.3 only; version 7.4 only; version 7.5 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Uclouvain Openjpeg: version 2.1.2 only
Published 2018-08-01. Last modified 2026-06-17.