Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:0044-1

Опубликовано: 09 янв. 2025
Источник: suse-cvrf

Описание

Security update for openjpeg2

This update for openjpeg2 fixes the following issues:

  • CVE-2024-56826: Fixed heap buffer overflow in bin/common/color.c (bsc#1235029)

Список пакетов

Container containers/lmcache-vllm-openai:0
libopenjp2-7-2.3.0-150000.3.18.1
Container containers/open-webui:0
libopenjp2-7-2.3.0-150000.3.18.1
Container containers/vllm-openai:0
libopenjp2-7-2.3.0-150000.3.18.1
Container suse/kiosk/firefox-esr:esr
libopenjp2-7-2.3.0-150000.3.18.1
Container suse/kiosk/firefox-esr:latest
libopenjp2-7-2.3.0-150000.3.18.1
Container suse/kiosk/xorg-client:latest
libopenjp2-7-2.3.0-150000.3.18.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
libopenjp2-7-2.3.0-150000.3.18.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
libopenjp2-7-2.3.0-150000.3.18.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS
libopenjp2-7-2.3.0-150000.3.18.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
libopenjp2-7-2.3.0-150000.3.18.1
Image ai_15_6
libopenjp2-7-2.3.0-150000.3.18.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
libopenjp2-7-2.3.0-150000.3.18.1
openjpeg2-2.3.0-150000.3.18.1
openjpeg2-devel-2.3.0-150000.3.18.1
SUSE Linux Enterprise Module for Package Hub 15 SP6
libopenjp2-7-32bit-2.3.0-150000.3.18.1
openSUSE Leap 15.6
libopenjp2-7-2.3.0-150000.3.18.1
libopenjp2-7-32bit-2.3.0-150000.3.18.1
openjpeg2-2.3.0-150000.3.18.1
openjpeg2-devel-2.3.0-150000.3.18.1

Описание

A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.


Затронутые продукты
Container containers/lmcache-vllm-openai:0:libopenjp2-7-2.3.0-150000.3.18.1
Container containers/open-webui:0:libopenjp2-7-2.3.0-150000.3.18.1
Container containers/vllm-openai:0:libopenjp2-7-2.3.0-150000.3.18.1
Container suse/kiosk/firefox-esr:esr:libopenjp2-7-2.3.0-150000.3.18.1

Ссылки