Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openjpeg2 | Dec 27, 2024 | Aug 30, 2017 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Oct 30, 2017 | Aug 30, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openjpeg-libs | Nov 19, 2019 | Aug 30, 2017 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openjpeg2 | Nov 19, 2019 | Aug 30, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Aug 30, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 30, 2017 |
| Suse | — | Upgrade openjpeg2-develUpgrade openjpeg2Upgrade libopenjp2-7 | May 19, 2018 | Aug 30, 2017 |
| Ubuntu | — | Upgrade openjpip-viewer (Ubuntu Pro)Upgrade openjpip-dec-server (Ubuntu Pro)Upgrade openjpip-server (Ubuntu Pro)Upgrade openjpip-viewer-xerces (Ubuntu Pro)Upgrade openjpeg-tools (Ubuntu Pro)Upgrade libopenjp2-7 (Ubuntu Pro) | Mar 22, 2023 | Aug 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub