NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Oct 30, 2017 | Aug 30, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openjpeg-libs | Dec 4, 2019 | Aug 30, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openjpeg-libs | Dec 18, 2019 | Aug 30, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openjpeg-libs | Nov 19, 2019 | Aug 30, 2017 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openjpeg2 | Nov 19, 2019 | Aug 30, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Aug 30, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 30, 2017 |
| Suse | — | Upgrade openjpeg2-develUpgrade openjpeg2Upgrade libopenjp2-7 | May 20, 2018 | Aug 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub