CVE-2013-6054
published 2013-12-12CVE-2013-6054: Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.17%
80.2th percentile
Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| uclouvain | openjpeg | <= 1.3 | — |
| uclouvain | openjpeg | >= 0 < 1.3+dfsg-4.7ubuntu1 | 1.3+dfsg-4.7ubuntu1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qj5m-cr8m-jr8v: Heap-based buffer overflow in OpenJPEG 1
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2013-6054 [HIGH] CWE-119 GHSA-qj5m-cr8m-jr8v: Heap-based buffer overflow in OpenJPEG 1
Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.
OSV
CVE-2013-6054: Heap-based buffer overflow in OpenJPEG 1
osv·2013-12-12·CVSS 7.5
CVE-2013-6054 [HIGH] CVE-2013-6054: Heap-based buffer overflow in OpenJPEG 1
Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.
Red Hat
openjpeg: heap-based buffer overflows in version 1.3
vendor_redhat·2013-12-04·CVSS 7.5
CVE-2013-6054 [HIGH] CWE-122 openjpeg: heap-based buffer overflows in version 1.3
openjpeg: heap-based buffer overflows in version 1.3
Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6054 CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 openjpeg: various flaws [epel-5]
bugzilla·2013-12-05·CVSS 5.0
CVE-2013-6054 [MEDIUM] CVE-2013-6054 CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 openjpeg: various flaws [epel-5]
CVE-2013-6054 CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 openjpeg: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 trac
Bugzilla
CVE-2013-6054 openjpeg: heap-based buffer overflows in version 1.3
bugzilla·2013-12-02·CVSS 7.5
CVE-2013-6054 [HIGH] CVE-2013-6054 openjpeg: heap-based buffer overflows in version 1.3
CVE-2013-6054 openjpeg: heap-based buffer overflows in version 1.3
Raphael Geissert discovered multiple heap-based buffer overflows in OpenJPEG. If a specially-crafted image were opened by an application linked against OpenJPEG, it could cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
These issues only affected the version of OpenJPEG as shipped in Red Hat Enterprise Linux 6 and EPEL 5 (version 1.3).
Discussion:
Created attachment 831466
proposed patch
---
Acknowledgements:
Red Hat would like to thank Raphael Geissert for reporting these issues during a review for EDF.
---
Created openjpeg tracking bugs for this issue:
Affects: epel-5 [bug 1038411]
---
This issue has been addressed in following prod
http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWShttp://osvdb.org/100639http://rhn.redhat.com/errata/RHSA-2013-1850.htmlhttp://seclists.org/oss-sec/2013/q4/412http://www.debian.org/security/2013/dsa-2808http://www.securityfocus.com/bid/64113http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWShttp://osvdb.org/100639http://rhn.redhat.com/errata/RHSA-2013-1850.htmlhttp://seclists.org/oss-sec/2013/q4/412http://www.debian.org/security/2013/dsa-2808http://www.securityfocus.com/bid/64113
2013-12-12
Published