REDHAT-BUG-2041479: Medium severity OpenJDK ImageIO vulnerability
A flaw was found in the way the TIFFNullDecompressor class implementation in the ImageIO component of OpenJDK performed reading of uncompressed TIFF files. A specially-crafted TIFF image could cause the decompressor to create image objects with an inconsistent state due to failure to fully read the image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2041479?
The severity of REDHAT-BUG-2041479 is classified as important.
How do I fix REDHAT-BUG-2041479?
To fix REDHAT-BUG-2041479, you should update the OpenJDK ImageIO component to the latest patched version.
What could happen if I don't address REDHAT-BUG-2041479?
If REDHAT-BUG-2041479 is not addressed, it may allow an attacker to create image objects in an inconsistent state, leading to potential application crashes or other issues.
Which versions are affected by REDHAT-BUG-2041479?
All versions of OpenJDK ImageIO that contain the vulnerable TIFFNullDecompressor implementation may be affected by REDHAT-BUG-2041479.
Is there a workaround for the REDHAT-BUG-2041479 vulnerability?
Currently, there are no effective workarounds available for REDHAT-BUG-2041479 other than applying the necessary updates.