First published: Thu Jan 07 2021(Updated: )
It was discovered that OpenJPEG incorrectly handled certain image data. An attacker could use this issue to cause OpenJPEG to crash, leading to a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libopenjp2-7 | <2.3.1-1ubuntu4.20.10.1 | 2.3.1-1ubuntu4.20.10.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/libopenjp3d7 | <2.3.1-1ubuntu4.20.10.1 | 2.3.1-1ubuntu4.20.10.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/libopenjpip7 | <2.3.1-1ubuntu4.20.10.1 | 2.3.1-1ubuntu4.20.10.1 |
Ubuntu Ubuntu | =20.10 | |
All of | ||
ubuntu/libopenjp2-7 | <2.3.1-1ubuntu4.20.04.1 | 2.3.1-1ubuntu4.20.04.1 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/libopenjp3d7 | <2.3.1-1ubuntu4.20.04.1 | 2.3.1-1ubuntu4.20.04.1 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/libopenjpip7 | <2.3.1-1ubuntu4.20.04.1 | 2.3.1-1ubuntu4.20.04.1 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability IDs for these OpenJPEG vulnerabilities are CVE-2020-27842, CVE-2020-27841, and CVE-2020-27824.
The severity of CVE-2020-27842 is not provided in the information provided.
To fix the OpenJPEG vulnerabilities, you need to update the affected software packages to version 2.3.1-1ubuntu4.20.10.1 (for Ubuntu 20.10) or version 2.3.1-1ubuntu4.20.04.1 (for Ubuntu 20.04).
You can find more information about CVE-2020-27842 at the following URL: https://ubuntu.com/security/CVE-2020-27842