A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qt5-qtwebengineUpgrade openjpegUpgrade chromium | Aug 22, 2024 | Jan 5, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 5, 2021 |
| Debian | — | Upgrade openjpeg2 | Feb 10, 2021 | Jan 5, 2021 |
| Freebsd | — | Upgrade chromium | Mar 5, 2021 | Mar 4, 2021 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg. | Jan 27, 2021 | Jan 5, 2021 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Mar 5, 2021 | Mar 2, 2021 |
| Microsoft Edge | — | Update Microsoft Edge to the latest version | Nov 17, 2021 | Mar 4, 2021 |
| Oracle Solaris | — | Upgrade image/library/openjpeg2 to version 2.4.0-11.4.31.0.1.88.1 on Solaris 11.4 | Mar 17, 2021 | Jan 5, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 5, 2021 |
| Suse | — | Upgrade chromedriverUpgrade chromium | Mar 9, 2021 | Jan 5, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub