First published: Wed Jan 01 2025(Updated: )
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjpeg2 | <=2.4.0-3<=2.5.0-2 | |
OpenJPEG |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56827 has a high severity level due to the potential for heap buffer overflow leading to application crashes.
To fix CVE-2024-56827, update the OpenJPEG package to version 2.5.0-3 or later.
CVE-2024-56827 affects OpenJPEG versions up to 2.4.0-3 and 2.5.0-2 on Debian-based systems.
CVE-2024-56827 exploits a heap buffer overflow in the opj_decompress utility under specific options.
The potential consequences of CVE-2024-56827 include application crashes and undefined behavior.