NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openjpeg | Uclouvain | * | 2.1.2 (including) |
Openjpeg | Ubuntu | trusty | * |
Openjpeg | Ubuntu | upstream | * |
Openjpeg | Ubuntu | vivid | * |
Openjpeg | Ubuntu | wily | * |
Openjpeg2 | Ubuntu | artful | * |
Openjpeg2 | Ubuntu | upstream | * |
Openjpeg2 | Ubuntu | zesty | * |