Описание
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | code not compiled |
| devel | not-affected | uses system openjpeg2 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/bionic | not-affected | code not compiled |
| esm-infra/focal | not-affected | uses system openjpeg2 |
| esm-infra/xenial | not-affected | code not compiled |
| focal | not-affected | uses system openjpeg2 |
| groovy | not-affected | uses system openjpeg2 |
| hirsute | not-affected | uses system openjpeg2 |
| impish | not-affected | uses system openjpeg2 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| eoan | DNE | |
| esm-apps/xenial | not-affected | code not present |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2.3.0-2+deb10u2build0.18.04.1 |
| devel | released | 2.3.1-1ubuntu5 |
| esm-apps/bionic | released | 2.3.0-2+deb10u2build0.18.04.1 |
| esm-apps/xenial | released | 2.1.2-1.1+deb9u5build0.16.04.1 |
| esm-infra-legacy/trusty | DNE | |
| esm-infra/focal | released | 2.3.1-1ubuntu4.20.04.1 |
| focal | released | 2.3.1-1ubuntu4.20.04.1 |
| groovy | released | 2.3.1-1ubuntu4.20.10.1 |
| hirsute | released | 2.3.1-1ubuntu5 |
| impish | released | 2.3.1-1ubuntu5 |
Показывать по
5.8 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free th ...
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
Уязвимость компонента jp2/opj_decompress.c библиотеки для кодирования и декодирования изображений OpenJPEG, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
5.8 Medium
CVSS2
6.5 Medium
CVSS3