The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openjpeg | Sep 20, 2017 | Aug 21, 2017 |
| Debian | — | Upgrade openjpeg2 | Jul 30, 2024 | Aug 21, 2017 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Oct 30, 2017 | Aug 21, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Aug 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 14, 2017 |
| Suse | — | Upgrade openjpeg2Upgrade openjpeg2-develUpgrade libopenjp2-7 | May 19, 2018 | Aug 21, 2017 |
| Ubuntu | — | Upgrade libopenjp2-7 (Ubuntu Pro) | Mar 22, 2023 | Aug 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub