CVE-2016-10504
MEDIUMOpenJPEG < 2.2.0 - Heap-Based Buffer Overflow in opj_mqc_byteout
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-10504. PoCs published by Ke Liu.
AI-analyzed exploit summary This exploit demonstrates a heap-buffer-overflow vulnerability in OpenJPEG's `opj_mqc_byteout` function, triggered by a malformed BMP file. The PoC causes an out-of-bounds write during compression, leading to a crash.
Description
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.
Exploits (1)
This exploit demonstrates a heap-buffer-overflow vulnerability in OpenJPEG's `opj_mqc_byteout` function, triggered by a malformed BMP file. The PoC causes an out-of-bounds write during compression, leading to a crash.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H