PatchSiren cyber security CVE debrief
CVE-2016-4797 Fedoraproject CVE debrief
CVE-2016-4797 is a denial-of-service vulnerability in OpenJPEG’s tile initialization logic. A crafted JP2 file can trigger a divide-by-zero in opj_tcd_init_tile in tcd.c, crashing the application. The issue is notable because it stems from an incorrect fix for CVE-2014-7947. NVD rates the issue as medium severity (CVSS 3.0 5.5).
- Vendor
- Fedoraproject
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-03
- Advisory updated
- 2026-05-13
Who should care
Security and platform teams that package, deploy, or embed OpenJPEG; Fedora maintainers and users of Fedora 23/24 packages identified as vulnerable; and any application that accepts untrusted JP2 files for preview, conversion, or analysis.
Technical summary
According to the NVD description, OpenJPEG versions before 2.1.1 can divide by zero in opj_tcd_init_tile within tcd.c when processing a crafted JP2 file. The weakness is categorized as CWE-369. The supplied NVD record also notes that the flaw exists because of an incorrect fix for CVE-2014-7947. The NVD CVSS 3.0 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating a crash-oriented availability impact with user interaction required.
Defensive priority
Medium
Recommended defensive actions
- Upgrade OpenJPEG to a version that includes the 2.1.1 fix or later.
- Review downstream packages and appliances that ship OpenJPEG, including Fedora 23/24 builds listed in the NVD CPE data.
- Restrict or sandbox handling of untrusted JP2 files in applications that use OpenJPEG.
- Validate vendor advisories and package announcements for patched builds before re-enabling JP2 ingestion workflows.
Evidence notes
Primary evidence comes from the official NVD record and its linked references. The NVD description states the divide-by-zero in opj_tcd_init_tile affects OpenJPEG before 2.1.1 and that it is tied to an incorrect prior fix for CVE-2014-7947. Supporting references include the oss-security mailing list post, a Red Hat bug record, the upstream OpenJPEG commit, an upstream issue, and Fedora package announcements. The NVD CPE criteria list vulnerable OpenJPEG versions up to 2.1.0 and Fedora 23/24 as affected.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-4797 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-4797
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-4797 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4797
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/uclouvain/openjpeg/commit/8f9cc62b3f9a1da9712329ddcedb9750d585505c
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/uclouvain/openjpeg/issues/733
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FFMOZOF2EI6N2CR23EQ5EATWLQKBMHW/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BJM23YERMEC6LCTWBUH7LZURGSLZDFDH/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFRD35RIPRCGZA5DKAKHZ62LMP2A5UT7/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.