Divide-by-zero vulnerability in the opjtcdinit_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
{ "vanir_signatures": [ { "signature_type": "Function", "target": { "file": "src/lib/openjp2/tcd.c", "function": "opj_tcd_init_tile" }, "id": "CVE-2016-4797-0cac461e", "digest": { "length": 9361.0, "function_hash": "257004248534814206722681566285479977596" }, "source": "https://github.com/uclouvain/openjpeg/commit/8f9cc62b3f9a1da9712329ddcedb9750d585505c", "deprecated": false, "signature_version": "v1" }, { "signature_type": "Line", "target": { "file": "src/lib/openjp2/tcd.c" }, "id": "CVE-2016-4797-d9f76175", "digest": { "threshold": 0.9, "line_hashes": [ "225049661102870250041549526641074616634", "73247418388560494446265847644653004742", "334601661058292120774571645982894165467", "175452125379047758074089300299006649918" ] }, "source": "https://github.com/uclouvain/openjpeg/commit/8f9cc62b3f9a1da9712329ddcedb9750d585505c", "deprecated": false, "signature_version": "v1" } ] }