Описание
Security update for openjpeg2
This update for openjpeg2 fixes the following issue
- CVE-2025-54874: openjpeg: missing error check can lead to the use of an uninitialized pointer and cause an out-of- bounds heap memory write (bsc#1247650).
Список пакетов
openSUSE Leap 16.0
libopenjp2-7-2.5.3-160000.4.1
libopenjp2-7-x86-64-v3-2.5.3-160000.4.1
openjpeg2-2.5.3-160000.4.1
openjpeg2-devel-2.5.3-160000.4.1
openjpeg2-devel-doc-2.5.3-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1247650
- SUSE CVE CVE-2025-54874 page
Описание
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
Затронутые продукты
openSUSE Leap 16.0:libopenjp2-7-2.5.3-160000.4.1
openSUSE Leap 16.0:libopenjp2-7-x86-64-v3-2.5.3-160000.4.1
openSUSE Leap 16.0:openjpeg2-2.5.3-160000.4.1
openSUSE Leap 16.0:openjpeg2-devel-2.5.3-160000.4.1
Ссылки
- CVE-2025-54874
- SUSE Bug 1247649