convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openjpeg | Aug 30, 2017 | Oct 3, 2016 |
| Debian | — | Upgrade openjpeg2 | Jul 30, 2024 | Oct 3, 2016 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Oct 30, 2017 | Oct 3, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openjpeg-libs | Dec 4, 2019 | Oct 3, 2016 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openjpeg-libs | Dec 18, 2019 | Oct 3, 2016 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openjpeg-libs | Nov 19, 2019 | Oct 3, 2016 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openjpeg2 | Nov 19, 2019 | Oct 3, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 3, 2016 |
| Suse | — | Upgrade libopenjpeg1Upgrade libopenjp2-7Upgrade openjpeg2Upgrade openjpeg2-develUpgrade openjpegUpgrade openjpeg-devel | Oct 12, 2016 | Oct 3, 2016 |
| Ubuntu | — | Upgrade openjpip-viewer (Ubuntu Pro)Upgrade openjpip-viewer-xerces (Ubuntu Pro)Upgrade openjpeg-tools (Ubuntu Pro)Upgrade openjpip-server (Ubuntu Pro)Upgrade openjpip-dec-server (Ubuntu Pro) | Mar 22, 2023 | Oct 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub