First published: Thu Sep 05 2019(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclouvain Openjpeg | <2.3.1 | |
Debian Debian Linux | =8.0 | |
debian/openjpeg2 | 2.4.0-3 2.5.0-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21010 is a vulnerability in OpenJPEG before 2.3.1 that has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
CVE-2018-21010 has a severity rating of 8.8, which is considered high.
OpenJPEG versions 2.1.2-1.1+ and 2.3.0-2+deb10u2, 2.4.0-3, and 2.5.0-2 are affected.
To fix CVE-2018-21010 in Ubuntu, update the openjpeg2 package to version 2.1.2-1.1+ or later.
To fix CVE-2018-21010 in Debian, update the openjpeg2 package to version 2.3.0-2+deb10u2, 2.4.0-3, or 2.5.0-2.