Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:13944

Опубликовано: 03 окт. 2025
Источник: rocky
Оценка: Important

Описание

Important: openjpeg2 security update

OpenJPEG is an open source library for reading and writing image files in JPEG2000 format.

Security Fix(es):

  • openjpeg: OpenJPEG OOB heap memory write (CVE-2025-54874)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
openjpeg2x86_644.el10_0.1openjpeg2-2.5.2-4.el10_0.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

CVSS3: 8
redhat
3 месяца назад

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

CVSS3: 9.8
nvd
3 месяца назад

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

CVSS3: 9.8
debian
3 месяца назад

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 thr ...

oracle-oval
3 месяца назад

ELSA-2025-13944: openjpeg2 security update (IMPORTANT)