In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openjpeg2 | May 15, 2025 | May 15, 2025 |
| Freebsd | — | Upgrade openjpeg | Jul 28, 2018 | Jul 27, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openjpeg-libs | Feb 22, 2021 | Dec 8, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openjpeg-libs | Dec 18, 2019 | Dec 8, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openjpeg-libs | Feb 3, 2021 | Dec 8, 2017 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openjpeg-libs | Apr 26, 2022 | Dec 8, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Dec 8, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 8, 2017 |
| Suse | — | Upgrade libopenjp2-7 | May 23, 2018 | Dec 8, 2017 |
| Ubuntu | — | Upgrade openjpeg-tools (Ubuntu Pro)Upgrade openjpip-server (Ubuntu Pro)Upgrade openjpip-viewer (Ubuntu Pro)Upgrade openjpip-dec-server (Ubuntu Pro)Upgrade openjpip-viewer-xerces (Ubuntu Pro) | Mar 22, 2023 | Dec 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub