CVE-2018-5785
published 2018-01-19CVE-2018-5785: In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers…
PriorityP425medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.33%
81.6th percentile
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjpeg2 | < openjpeg2 2.3.0-2 (bookworm) | openjpeg2 2.3.0-2 (bookworm) |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.14.04.1 | 1:60.5.1+build2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.16.04.1 | 1:60.5.1+build2-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.18.04.1 | 1:60.5.1+build2-0ubuntu0.18.04.1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2 | 2.3.0-2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2 | 2.3.0-2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2 | 2.3.0-2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2 | 2.3.0-2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2build0.18.04.1 | 2.3.0-2build0.18.04.1 |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJPEG vulnerabilities
vendor_ubuntu·2019-08-21·CVSS 9.8
CVE-2017-17480 [CRITICAL] OpenJPEG vulnerabilities
Title: OpenJPEG vulnerabilities
Summary: Several security issues were fixed in OpenJPEG.
It was discovered that OpenJPEG incorrectly handled certain PGX files. An
attacker could possibly use this issue to cause a denial of service or possibly
remote code execution. (CVE-2017-17480)
It was discovered that OpenJPEG incorrectly handled certain files. An attacker
could possibly use this issue to cause a denial of service. (CVE-2018-14423)
It was discovered that OpenJPEG incorrectly handled certain PNM files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-18088)
It was discovered that OpenJPEG incorrectly handled certain BMP files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-5785, CVE-2018-6616)
Instructions: In gene
Red Hat
openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c
vendor_redhat·2018-01-19·CVSS 6.5
CVE-2018-5785 [MEDIUM] CWE-190 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c
openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-5785: openjpeg2 - In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left ...
vendor_debian·2018·CVSS 6.5
CVE-2018-5785 [MEDIUM] CVE-2018-5785: openjpeg2 - In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left ...
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
Scope: local
bookworm: resolved (fixed in 2.3.0-2)
bullseye: resolved (fixed in 2.3.0-2)
forky: resolved (fixed in 2.3.0-2)
sid: resolved (fixed in 2.3.0-2)
trixie: resolved (fixed in 2.3.0-2)
GHSA
GHSA-7pgc-fq24-w5rr: In OpenJPEG 2
ghsa_unreviewed·2022-05-13
CVE-2018-5785 [MEDIUM] CWE-190 GHSA-7pgc-fq24-w5rr: In OpenJPEG 2
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
OSV
openjpeg2 vulnerabilities
osv·2019-08-21·CVSS 9.8
CVE-2017-17480 [CRITICAL] openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
It was discovered that OpenJPEG incorrectly handled certain PGX files. An
attacker could possibly use this issue to cause a denial of service or possibly
remote code execution. (CVE-2017-17480)
It was discovered that OpenJPEG incorrectly handled certain files. An attacker
could possibly use this issue to cause a denial of service. (CVE-2018-14423)
It was discovered that OpenJPEG incorrectly handled certain PNM files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-18088)
It was discovered that OpenJPEG incorrectly handled certain BMP files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2018-5785, CVE-2018-6616)
OSV
thunderbird vulnerabilities
osv·2019-02-26·CVSS 5.5
CVE-2016-5824 thunderbird vulnerabilities
thunderbird vulnerabilities
A use-after-free was discovered in libical. If a user were tricked in to
opening a specially crafted ICS calendar file, an attacker could
potentially exploit this to cause a denial of service. (CVE-2016-5824)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-18356, CVE-2018-18500, CVE-2019-5785)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
gain additional privileges by escaping the sandbox, or execute arbitr
OSV
CVE-2018-5785: In OpenJPEG 2
osv·2018-01-19·CVSS 6.5
CVE-2018-5785 [MEDIUM] CVE-2018-5785: In OpenJPEG 2
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
No detection rules found.
No public exploits indexed.
arXiv
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
arxiv_fulltext·2025-08-14
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
Vercation: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
Yiran Cheng12,
Ting Zhang35,
Lwin Khin Shar3,
Shouguo Yang4,
Chaopeng Dong12,
David Lo3,
Shichao Lv125,
Zhiqiang Shi12,
Limin Sun12
1 Beijing Key Laboratory of IOT Information Security Technology,
Institute of Information Engineering, Beijing, China
2 School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China
3 Singapore Management University, Singapore
4 Zhongguancun Laboratory, Beijing, China
[email protected], [email protected], [email protected], \yangshouguo, dongchaopeng\@iie.ac.cn, [email protected], \lvshichao, shizhiqiang, sunlimin\@iie.ac.cn
Journal of \ Class Files, Vol. 14, No. 8, August 2025
Shell et al.: A Sample Article
arXiv
Data Flows in You: Benchmarking and Improving Static Data-flow Analysis on Binary Executables
arxiv_fulltext·2025-05-30
Data Flows in You: Benchmarking and Improving Static Data-flow Analysis on Binary Executables
Data Flows in You: Benchmarking and Improving Static Data-flow Analysis on Binary Executables
Nicolaas Weideman1,
Sima Arasteh2,
Mukund Raghothaman2,
Jelena Mirkovic3,
Christophe Hauser4
1USC Information Sciences Institute, Los Angeles, CA, USA
[email protected]
2University of Southern California, Los Angeles, CA, USA
\arasteh, raghotha\@usc.edu
3USC Information Sciences Institute, Los Angeles, CA, USA
[email protected]
4Dartmouth College, Hanover, NH, USA
[email protected]
## Abstract
Data-flow analysis is a critical component of security research. Theoretically, accurate data-flow analysis in binary executables is an undecidable problem, due to complexities of binary code. Practically, many binary analysis engines offer some data-flow analysis capability, but w
Bugzilla
CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
bugzilla·2018-01-23·CVSS 6.5
CVE-2018-5785 [MEDIUM] CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [epel-all]
bugzilla·2018-01-23·CVSS 6.5
CVE-2018-5785 [MEDIUM] CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [epel-all]
CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2018-5785 openjpeg2: openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
bugzilla·2018-01-23·CVSS 6.5
CVE-2018-5785 [MEDIUM] CVE-2018-5785 openjpeg2: openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
CVE-2018-5785 openjpeg2: openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2018-5785 mingw-openjpeg2: openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
bugzilla·2018-01-23·CVSS 6.5
CVE-2018-5785 [MEDIUM] CVE-2018-5785 mingw-openjpeg2: openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
CVE-2018-5785 mingw-openjpeg2: openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c
bugzilla·2018-01-23·CVSS 6.5
CVE-2018-5785 [MEDIUM] CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c
CVE-2018-5785 openjpeg: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c
A flaw was found in OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
Reference:
https://github.com/uclouvain/openjpeg/issues/1057
Discussion:
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1537761]
Created openjpeg tracking bugs for this issue:
Affects: epel-all [bug 1537762]
Affects: fedora-all [bug 1537759]
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1537760]
---
Analysis:
Running openjpeg compiled with UBSAN, i observe the following:
2018-01-19
Published