An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade openjpeg-debuginfoUpgrade openjpeg-libsUpgrade openjpegUpgrade openjpeg-devel | Mar 30, 2017 | Dec 27, 2016 |
| Debian | — | Upgrade openjpeg2 | Jan 22, 2017 | Dec 27, 2016 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Oct 30, 2017 | Oct 23, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade openjpeg-libs | Aug 28, 2019 | Aug 1, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openjpeg-libs | Aug 28, 2019 | Aug 1, 2018 |
| Oracle_linux | — | Upgrade openjpeg-libsUpgrade openjpeg-develUpgrade openjpeg | Mar 23, 2017 | Nov 2, 2016 |
| Redhat_linux | — | Upgrade openjpegUpgrade openjpeg-develUpgrade openjpeg-libsUpgrade openjpeg-debuginfo | Mar 23, 2017 | Dec 27, 2016 |
| Suse | — | Upgrade libopenjp2-7Upgrade openjpeg2-develUpgrade openjpeg2 | Dec 28, 2016 | Dec 27, 2016 |
| Ubuntu | — | Upgrade openjpeg2 | Nov 19, 2024 | Aug 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub