PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-4797 Fedoraproject CVE debrief

CVE-2016-4797 is a denial-of-service vulnerability in OpenJPEG’s tile initialization logic. A crafted JP2 file can trigger a divide-by-zero in opj_tcd_init_tile in tcd.c, crashing the application. The issue is notable because it stems from an incorrect fix for CVE-2014-7947. NVD rates the issue as medium severity (CVSS 3.0 5.5).

Vendor
Fedoraproject
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-03
Original CVE updated
2026-05-13
Advisory published
2017-02-03
Advisory updated
2026-05-13

Who should care

Security and platform teams that package, deploy, or embed OpenJPEG; Fedora maintainers and users of Fedora 23/24 packages identified as vulnerable; and any application that accepts untrusted JP2 files for preview, conversion, or analysis.

Technical summary

According to the NVD description, OpenJPEG versions before 2.1.1 can divide by zero in opj_tcd_init_tile within tcd.c when processing a crafted JP2 file. The weakness is categorized as CWE-369. The supplied NVD record also notes that the flaw exists because of an incorrect fix for CVE-2014-7947. The NVD CVSS 3.0 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating a crash-oriented availability impact with user interaction required.

Defensive priority

Medium

Recommended defensive actions

  • Upgrade OpenJPEG to a version that includes the 2.1.1 fix or later.
  • Review downstream packages and appliances that ship OpenJPEG, including Fedora 23/24 builds listed in the NVD CPE data.
  • Restrict or sandbox handling of untrusted JP2 files in applications that use OpenJPEG.
  • Validate vendor advisories and package announcements for patched builds before re-enabling JP2 ingestion workflows.

Evidence notes

Primary evidence comes from the official NVD record and its linked references. The NVD description states the divide-by-zero in opj_tcd_init_tile affects OpenJPEG before 2.1.1 and that it is tied to an incorrect prior fix for CVE-2014-7947. Supporting references include the oss-security mailing list post, a Red Hat bug record, the upstream OpenJPEG commit, an upstream issue, and Fedora package announcements. The NVD CPE criteria list vulnerable OpenJPEG versions up to 2.1.0 and Fedora 23/24 as affected.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-4797 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-4797

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-4797 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-4797

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/uclouvain/openjpeg/commit/8f9cc62b3f9a1da9712329ddcedb9750d585505c

    [email protected] - Issue Tracking, Patch, Third Party Advisory

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/uclouvain/openjpeg/issues/733

    [email protected] - Issue Tracking, Patch, Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FFMOZOF2EI6N2CR23EQ5EATWLQKBMHW/

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BJM23YERMEC6LCTWBUH7LZURGSLZDFDH/

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DFRD35RIPRCGZA5DKAKHZ62LMP2A5UT7/

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.