USN-7083-1: OpenJPEG vulnerabilities
It was discovered that OpenJPEG incorrectly handled certain memory operations when using the command line "-ImgDir" in a directory with a large number of files, leading to an integer overflow vulnerability. An attacker could potentially use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-29338) It was discovered that OpenJPEG incorrectly handled decompressing certain .j2k files in sycc420torgb, leading to a heap-based buffer overflow vulnerability. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to execute arbitrary code. (CVE-2021-3575) It was discovered that OpenJPEG incorrectly handled certain memory operations in the opj2decompress program. An attacker could potentially use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-1122)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7083-1?
The severity of USN-7083-1 is categorized as a denial of service vulnerability due to an integer overflow issue.
How do I fix USN-7083-1?
To fix USN-7083-1, update the affected packages to the versions specified in the advisory, such as libopenjp2-7 version 2.5.0-2ubuntu1.1 or higher.
Which software is affected by USN-7083-1?
USN-7083-1 affects multiple Ubuntu packages, including libopenjp2-7 and libopenjpip7 across various Ubuntu versions.
Can USN-7083-1 affect my system?
Yes, if you are using the affected versions of packages on Ubuntu, your system may be vulnerable to denial of service attacks.
What should I do if I cannot update the packages due to USN-7083-1?
If you cannot update the packages for USN-7083-1, consider mitigating exposure by limiting access to your applications utilizing these libraries.