{"id":"CVE-2015-8871","details":"Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.","modified":"2026-04-10T03:45:35.677515Z","published":"2016-09-21T14:25:00Z","related":["SUSE-SU-2017:2144-1","openSUSE-SU-2017:2567-1"],"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3665"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2015/09/15/4"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/05/13/1"},{"type":"ADVISORY","url":"https://github.com/uclouvain/openjpeg/blob/master/CHANGELOG.md"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201612-26"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2015/09/15/4"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2016/05/13/1"},{"type":"FIX","url":"https://github.com/uclouvain/openjpeg/commit/940100c28ae28931722290794889cf84a92c5f6f"},{"type":"FIX","url":"https://github.com/uclouvain/openjpeg/issues/563"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1263359"},{"type":"REPORT","url":"https://github.com/uclouvain/openjpeg/commit/940100c28ae28931722290794889cf84a92c5f6f"},{"type":"REPORT","url":"https://github.com/uclouvain/openjpeg/issues/563"},{"type":"WEB","url":"http://www.securitytracker.com/id/1038623"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}