Search CVE reports
51 – 60 of 79 results
Some fixes available 6 of 7
An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.
2 affected packages
openjpeg2, openjpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg2 | — | — | — | Fixed |
openjpeg | — | — | — | Not in release |
Some fixes available 6 of 7
A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or...
2 affected packages
openjpeg, openjpeg2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg | — | — | — | Not in release |
openjpeg2 | — | — | — | Fixed |
Some fixes available 1 of 3
Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.
2 affected packages
openjpeg2, openjpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg2 | — | — | — | Not affected |
openjpeg | — | — | — | Not in release |
Some fixes available 2 of 5
Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.
3 affected packages
ghostscript, openjpeg, openjpeg2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | Not affected | Not affected | Not affected | Not affected |
openjpeg | Not in release | Not in release | Not in release | Not in release |
openjpeg2 | Not affected | Not affected | Not affected | Not affected |
NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow...
2 affected packages
openjpeg, openjpeg2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg | — | — | — | Not in release |
openjpeg2 | — | — | — | Not affected |
Some fixes available 2 of 3
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.
2 affected packages
openjpeg, openjpeg2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg | — | — | — | Not in release |
openjpeg2 | — | — | — | Not affected |
Some fixes available 2 of 5
The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in...
3 affected packages
ghostscript, openjpeg, openjpeg2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
ghostscript | — | Not affected | Not affected | Not affected |
openjpeg | — | Not in release | Not in release | Not in release |
openjpeg2 | — | Not affected | Not affected | Fixed |
Some fixes available 1 of 2
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of...
2 affected packages
openjpeg, openjpeg2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg | — | — | — | Not in release |
openjpeg2 | — | — | — | Not affected |
Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
2 affected packages
openjpeg, openjpeg2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg | — | — | — | — |
openjpeg2 | — | — | — | — |
Some fixes available 1 of 2
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
2 affected packages
openjpeg2, openjpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
openjpeg2 | — | — | — | Not affected |
openjpeg | — | — | — | Not in release |