Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1122

Опубликовано: 13 июл. 2021
Источник: redhat
CVSS3: 5.1

Описание

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

A flaw was found in the opj2_decompress program in openjpeg2 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

Отчет

This flaw affects the opj2_compress utility but is not in the openjpeg2 library. Therefore, the attack vector is local to the opj2_compress utility and would require an attacker to convince a user to open a directory with an extremely large number of files using opj2_compress, or a script to be feeding such arbitrary, untrusted files to opj2_compress.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegOut of support scope
Red Hat Enterprise Linux 7openjpegOut of support scope
Red Hat Enterprise Linux 7openjpeg2Out of support scope
Red Hat Enterprise Linux 8gimp:flatpak/openjpeg2Not affected
Red Hat Enterprise Linux 8inkscape:flatpak/openjpeg2Not affected
Red Hat Enterprise Linux 8libreoffice:flatpak/openjpeg2Not affected
Red Hat Enterprise Linux 9libreoffice:flatpak/openjpeg2Not affected
Red Hat Enterprise Linux 8openjpeg2FixedRHSA-2022:764508.11.2022
Red Hat Enterprise Linux 9openjpeg2FixedRHSA-2022:820715.11.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-665->CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2067052openjpeg: segmentation fault in opj2_decompress due to uninitialized pointer

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 3 лет назад

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

CVSS3: 5.5
nvd
около 3 лет назад

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

CVSS3: 5.5
debian
около 3 лет назад

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in ...

rocky
больше 2 лет назад

Low: openjpeg2 security update

rocky
больше 2 лет назад

Low: openjpeg2 security update

5.1 Medium

CVSS3