CVE-2022-1122
published 2022-03-29CVE-2022-1122: A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.08%
61.6th percentile
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openjpeg2 | < openjpeg2 2.5.0-1 (bookworm) | openjpeg2 2.5.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.4.0-3+deb11u1 | 2.4.0-3+deb11u1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-1 | 2.5.0-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-1 | 2.5.0-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-1 | 2.5.0-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.1-1ubuntu4.20.04.3 | 2.3.1-1ubuntu4.20.04.3 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.4.0-6ubuntu0.2 | 2.4.0-6ubuntu0.2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-2ubuntu0.2 | 2.5.0-2ubuntu0.2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.1+deb9u6ubuntu0.1~esm6 | 2.1.2-1.1+deb9u6ubuntu0.1~esm6 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2+deb10u2ubuntu0.1~esm3 | 2.3.0-2+deb10u2ubuntu0.1~esm3 |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJPEG vulnerabilities
vendor_ubuntu·2024-11-05·CVSS 5.5
CVE-2021-3575 [MEDIUM] OpenJPEG vulnerabilities
Title: OpenJPEG vulnerabilities
Summary: Several security issues were fixed in OpenJPEG.
It was discovered that OpenJPEG incorrectly handled certain memory
operations when using the command line "-ImgDir" in a directory with a
large number of files, leading to an integer overflow vulnerability. An
attacker could potentially use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-29338)
It was discovered that OpenJPEG incorrectly handled decompressing certain
.j2k files in sycc420_to_rgb, leading to a heap-based buffer overflow
vulnerability. If a user or automated system were tricked into opening
a specially crafted file, an attacker could possibly use this issue to
execute arbitrary code.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Security (OpenJPEG) — CVE-2022-1122
vendor_oracle·2023-07-15·CVSS 5.5
CVE-2022-1122 [MEDIUM] Oracle Oracle Supply Chain Risk Matrix: Security (OpenJPEG) — CVE-2022-1122
Oracle Oracle Supply Chain Risk Matrix: Security (OpenJPEG) vulnerability
CVE: CVE-2022-1122
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (OpenJPEG) — CVE-2022-1122
vendor_oracle·2023-01-15·CVSS 5.5
CVE-2022-1122 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (OpenJPEG) — CVE-2022-1122
Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (OpenJPEG) vulnerability
CVE: CVE-2022-1122
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2023 (JAN 2023)
Debian
CVE-2022-1122: openjpeg2 - A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it...
vendor_debian·2022·CVSS 5.5
CVE-2022-1122 [MEDIUM] CVE-2022-1122: openjpeg2 - A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it...
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Scope: local
bookworm: resolved (fixed in 2.5.0-1)
bullseye: resolved (fixed in 2.4.0-3+deb11u1)
forky: resolved (fixed in 2.5.0-1)
sid: resolved (fixed in 2.5.0-1)
trixie: resolved (fixed in 2.5.0-1)
Red Hat
openjpeg: segmentation fault in opj2_decompress due to uninitialized pointer
vendor_redhat·2021-07-13·CVSS 5.5
CVE-2022-1122 [MEDIUM] CWE-824 openjpeg: segmentation fault in opj2_decompress due to uninitialized pointer
openjpeg: segmentation fault in opj2_decompress due to uninitialized pointer
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
A flaw was found in the opj2_decompress program in openjpeg2 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Statement: This flaw affects the opj2_compress utility but is not in the openjpeg2
OSV
openjpeg2 vulnerabilities
osv·2024-11-05·CVSS 5.5
CVE-2021-29338 [MEDIUM] openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
It was discovered that OpenJPEG incorrectly handled certain memory
operations when using the command line "-ImgDir" in a directory with a
large number of files, leading to an integer overflow vulnerability. An
attacker could potentially use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2021-29338)
It was discovered that OpenJPEG incorrectly handled decompressing certain
.j2k files in sycc420_to_rgb, leading to a heap-based buffer overflow
vulnerability. If a user or automated system were tricked into opening
a specially crafted file, an attacker could possibly use this issue to
execute arbitrary code. (CVE-2021-3575)
It was discovered that OpenJPEG incorrectly ha
GHSA
GHSA-4x8v-rchj-qvpf: A flaw was found in the opj2_decompress program in openjpeg2 2
ghsa_unreviewed·2022-03-30
CVE-2022-1122 [MEDIUM] CWE-665 GHSA-4x8v-rchj-qvpf: A flaw was found in the opj2_decompress program in openjpeg2 2
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
OSV
CVE-2022-1122: A flaw was found in the opj2_decompress program in openjpeg2 2
osv·2022-03-29·CVSS 5.5
CVE-2022-1122 [MEDIUM] CVE-2022-1122: A flaw was found in the opj2_decompress program in openjpeg2 2
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
No detection rules found.
No public exploits indexed.
https://github.com/uclouvain/openjpeg/issues/1368https://lists.debian.org/debian-lts-announce/2022/04/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MIWSQFQWXDU4MT3XTVAO6HC7TVL3NHS7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMKBAMK2CAM5TMC5TODKVCE5AAPTD5YV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROSN5NRUFOH7HGLJ4ZSKPGAKLFXJALW4/https://security.gentoo.org/glsa/202209-04https://github.com/uclouvain/openjpeg/issues/1368https://lists.debian.org/debian-lts-announce/2022/04/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2025/04/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MIWSQFQWXDU4MT3XTVAO6HC7TVL3NHS7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RMKBAMK2CAM5TMC5TODKVCE5AAPTD5YV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ROSN5NRUFOH7HGLJ4ZSKPGAKLFXJALW4/https://security.gentoo.org/glsa/202209-04
2022-03-29
Published