USN-7223-1: OpenJPEG vulnerabilities
Frank Zeng discovered that OpenJPEG incorrectly handled memory when using the decompression utility. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-56826, CVE-2024-56827)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7223-1?
USN-7223-1 has a critical severity level due to a potential denial of service and arbitrary code execution vulnerabilities.
How do I fix USN-7223-1?
To fix USN-7223-1, you should update the affected packages, specifically to versions 2.5.0-2ubuntu1.2 or higher for libopenjp2-7 and libopenjp2-tools depending on your Ubuntu version.
Which Ubuntu versions are affected by USN-7223-1?
USN-7223-1 affects Ubuntu versions 24.10, 24.04, 22.04, 20.04, and 18.04.
What packages are impacted by USN-7223-1?
The impacted packages in USN-7223-1 are libopenjp2-7 and libopenjp2-tools.
What are the consequences of not addressing USN-7223-1?
Failing to address USN-7223-1 could expose your system to potential denial of service attacks and unauthorized code execution risks.