There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 5, 2021 |
| Debian | — | Upgrade openjpeg2 | Feb 10, 2021 | Jan 5, 2021 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Jan 27, 2021 | Jan 5, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openjpeg-libs | May 25, 2022 | Jan 5, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openjpeg-libs | Jun 17, 2022 | Jan 5, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openjpeg2 | Feb 2, 2021 | Jan 5, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openjpeg2 | Aug 10, 2021 | Jan 5, 2021 |
| Oracle Solaris | — | Upgrade image/library/openjpeg2 to version 2.4.0-11.4.31.0.1.88.1 on Solaris 11.4 | Mar 17, 2021 | Jan 5, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 5, 2021 |
| Suse | — | Upgrade libopenjp2-7-32bitUpgrade libopenjp2-7Upgrade openjpeg2-develUpgrade openjpeg2 | Aug 9, 2024 | Jan 5, 2021 |
| Ubuntu | — | Upgrade libopenjp2-7Upgrade libgs9Upgrade libopenjp3d7 (Ubuntu Pro)Upgrade libopenjpip7 (Ubuntu Pro)Upgrade ghostscriptUpgrade libopenjpip7Upgrade libopenjp3d7Upgrade libopenjp2-7 (Ubuntu Pro) | Jan 8, 2021 | Jan 5, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub