REDHAT-BUG-1957616: Medium severity openjpeg vulnerability
Published May 6, 2021
·Updated
Decompressing a crafted .j2k file may lead to heap-buffer-overflow in color.c:379:42 in sycc420torgb.
Reference:
https://github.com/uclouvain/openjpeg/issues/1347
Affected Software
1 affected component
uclouvain openjpeg
Event History
May 6, 2021
Data Sourced
via Red Hat·07:30 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1957616?
The vulnerability is categorized as a heap-buffer-overflow, which can lead to critical security issues such as arbitrary code execution.
2
How do I fix REDHAT-BUG-1957616?
To fix REDHAT-BUG-1957616, update to the latest version of UCLouvain OpenJPEG that addresses this vulnerability.
3
What software is affected by REDHAT-BUG-1957616?
The vulnerability affects UCLouvain OpenJPEG software when processing crafted .j2k files.
4
What is the cause of REDHAT-BUG-1957616?
REDHAT-BUG-1957616 is caused by a flaw in the sycc420_to_rgb function leading to heap-buffer overflow during decompression.
5
Is there a workaround for REDHAT-BUG-1957616?
A temporary workaround for REDHAT-BUG-1957616 is to avoid opening untrusted .j2k files until a patch is applied.