You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A vulnerability identified as CVE-2016-9534 was discovered and fixed in LibTiff. However, related file isn't updated in the OpenJPEG project.
Details
This was fixed on LibTiff with the following commit: vadz/libtiff@83a4b92, which amended the TIFFFlushData1 function located in libtiff/tif_write.c file.
The OpenJPEG project contains an identical TIFFFlushData1 function in the thirdparty/libtiff/tif_write.c file, which has not been updated.
Summary
A vulnerability identified as CVE-2016-9534 was discovered and fixed in LibTiff. However, related file isn't updated in the OpenJPEG project.
Details
This was fixed on LibTiff with the following commit: vadz/libtiff@83a4b92, which amended the TIFFFlushData1 function located in libtiff/tif_write.c file.
The OpenJPEG project contains an identical TIFFFlushData1 function in the thirdparty/libtiff/tif_write.c file, which has not been updated.
References
https://nvd.nist.gov/vuln/detail/CVE-2016-9534
https://my.f5.com/manage/s/article/K34527393
vadz/libtiff@83a4b92
openjpeg version
All versions prior to 2.5.2, which is the latest version at the time of this report, are potentially affected by this unpatched vulnerability.
Report Origin
The bug is reported by a tool developed at CAST
The text was updated successfully, but these errors were encountered: