A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openjpeg2 | Jan 22, 2017 | Dec 27, 2016 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Oct 30, 2017 | Oct 23, 2017 |
| Oracle Missing Cpu Jul 2019 | — | Apply the July 2019 Critical Patch Update (CPU) for Oracle Database | Aug 7, 2019 | Aug 1, 2018 |
| Suse | — | Upgrade libopenjp2-7Upgrade openjpeg2Upgrade openjpeg2-devel | Dec 28, 2016 | Dec 27, 2016 |
| Ubuntu | — | Upgrade openjpeg2 | Nov 19, 2024 | Aug 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub