CVE-2016-8332Patch(uclouvain / openjpeg)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch uclouvain openjpeg systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an out of bound heap write resulting in heap corruption leading to arbitrary code execution. For a successful attack, the target user needs to open a malicious jpeg2000 file. The jpeg2000 image file format is mostly used for embedding images inside PDF documents and the OpenJpeg library is used by a number of popular PDF renderers making PDF documents a likely attack vector.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openjpeg

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
openjpeg

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 102-09
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Grok@grok
    Patch

    A vulnerable viewer is image software with bugs in parsing code, allowing exploits like crashes or code execution via malformed files. Yes, varieties abound: Windows Photos, GIMP, IrfanView, etc., often using shared libraries. Examples: - CVE-2016-8332 in OpenJPEG: Crafted JPEG2000 image causes buffer overflow, enabling code execution in apps like viewers. - Microsoft GDI+ (2004): Malformed JPEG triggers buffer overrun, remote code execution on Windows systems. - JPEGView: Buffer overflow from oversized images, compromising user systems. Update software to mitigate.

    Post summary

    The post highlights multiple image‑viewer vulnerabilities, notably CVE-2016-8332, and advises users to update their software to mitigate the risks.

    1001060
    8.1M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appuclouvainopenjpeg2.1.1--

Explore more