{"id":"CVE-2016-7163","details":"Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.","modified":"2026-08-07T14:49:14.504294Z","published":"2016-09-21T14:25:28.550Z","related":["SUSE-SU-2017:2144-1","openSUSE-SU-2017:2567-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"23"},{"last_affected":"23"},{"introduced":"24"},{"last_affected":"24"},{"introduced":"25"},{"last_affected":"25"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"},{"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_desktop","cpes":["cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:o:redhat:enterprise_linux_eus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.4"},{"last_affected":"7.4"},{"introduced":"7.5"},{"last_affected":"7.5"},{"introduced":"7.6"},{"last_affected":"7.6"},{"introduced":"7.7"},{"last_affected":"7.7"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_eus"},{"cpes":["cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_server"},{"vendor_product":"redhat:enterprise_linux_server_aus","cpes":["cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.4"},{"last_affected":"7.4"},{"introduced":"7.6"},{"last_affected":"7.6"},{"introduced":"7.7"},{"last_affected":"7.7"}],"source":"CPE_STRING"},{"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_server_tus","cpes":["cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.6"},{"last_affected":"7.6"},{"introduced":"7.7"},{"last_affected":"7.7"}]},{"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux_workstation","cpes":["cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0"},{"last_affected":"6.0"},{"introduced":"7.0"},{"last_affected":"7.0"}]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2T6IQAMS4W65MGP7UW5FPE22PXELTK5D/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/66BWMMMWXH32J5AOGLAJGZA3GH5LZHXH/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQ2IIIQSJ3J4MONBOGCG6XHLKKJX2HKM/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4IRSGYMBSHCBZP23CUDIRJ3LBKH6ZJ7/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYLOX7PZS3ZUHQ6RGI3M6H27B7I5ZZ26/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGKSEWWWED77Q5ZHK4OA2EKSJXLRU3MK/"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0559.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0838.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3665"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/09/08/3"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/09/08/6"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/92897"},{"type":"FIX","url":"https://github.com/uclouvain/openjpeg/commit/c16bc057ba3f125051c9966cf1f5b68a05681de4"},{"type":"FIX","url":"https://github.com/uclouvain/openjpeg/commit/ef01f18dfc6780b776d0674ed3e7415c6ef54d24"},{"type":"FIX","url":"https://github.com/uclouvain/openjpeg/issues/826"},{"type":"FIX","url":"https://github.com/uclouvain/openjpeg/pull/809"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/uclouvain/openjpeg","events":[{"introduced":"0"},{"fixed":"3d7cde5fc9fbc5618d02160900d32e02ed12a00e"},{"fixed":"c16bc057ba3f125051c9966cf1f5b68a05681de4"},{"fixed":"ef01f18dfc6780b776d0674ed3e7415c6ef54d24"}],"database_specific":{"cpe":"cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.2.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"database_specific":{"vanir_signatures":[{"target":{"file":"src/lib/openjp2/pi.c"},"deprecated":false,"digest":{"line_hashes":["185758999126045357971661671097814027204","86990504606690239380690591281970397774","317109803081451321303173666652321153890","146470900076975004561247892323613665606"],"threshold":0.9},"id":"CVE-2016-7163-05a5f81d","signature_type":"Line","signature_version":"v1","source":"https://github.com/uclouvain/openjpeg/commit/c16bc057ba3f125051c9966cf1f5b68a05681de4"},{"source":"https://github.com/uclouvain/openjpeg/commit/c16bc057ba3f125051c9966cf1f5b68a05681de4","target":{"file":"src/lib/openjp2/pi.c","function":"opj_pi_create_decode"},"deprecated":false,"digest":{"function_hash":"327494365687452293443704431018112264625","length":2876},"id":"CVE-2016-7163-d9f02d1b","signature_type":"Function","signature_version":"v1"},{"target":{"file":"src/lib/openjp2/pi.c","function":"opj_pi_create_decode"},"deprecated":false,"digest":{"function_hash":"202036459876181118633764252559168912195","length":2957},"id":"CVE-2016-7163-e0dd0bb1","signature_type":"Function","signature_version":"v1","source":"https://github.com/uclouvain/openjpeg/commit/ef01f18dfc6780b776d0674ed3e7415c6ef54d24"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/uclouvain/openjpeg/commit/ef01f18dfc6780b776d0674ed3e7415c6ef54d24","target":{"file":"src/lib/openjp2/pi.c"},"deprecated":false,"digest":{"line_hashes":["101491955642050062039341120958308977673","292105675131205126059570189938538731622","174113429180073947026689323121376750221","64243987556959019689011967934429915812"],"threshold":0.9},"id":"CVE-2016-7163-f3f83cb3"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7163.json","vanir_signatures_modified":"2026-08-07T14:49:14Z"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}