CVE-2023-39327
published 2024-07-13CVE-2023-39327: A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the…
PriorityP417medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
0.53%
41.1th percentile
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.12 | 9.55.0~dfsg1-0ubuntu5.12 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.7 | 10.02.1~dfsg1-0ubuntu7.7 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 | 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 | 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.15+esm1 | 9.50~dfsg-5ubuntu4.15+esm1 |
| debian | openjpeg2 | — | — |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 4.3
CVE-2025-27835 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue
Ubuntu
OpenJPEG vulnerability
vendor_ubuntu·2024-09-26
CVE-2023-39327 OpenJPEG vulnerability
Title: OpenJPEG vulnerability
Summary: OpenJPEG could be made to crash if it opened a specially crafted file.
It was discovered that OpenJPEG could enter a large loop and continuously
print warning messages when given specially crafted input. An attacker
could potentially use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openjpeg: Malicious files can cause the program to enter a large loop
vendor_redhat·2024-07-04·CVSS 4.3
CVE-2023-39327 [MEDIUM] CWE-400 openjpeg: Malicious files can cause the program to enter a large loop
openjpeg: Malicious files can cause the program to enter a large loop
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
Package: openjpeg (Red Hat Enterprise Linux 6) - Out of support scope
Package: openjpeg (Red Hat Enterprise Linux 7) - Out of support scope
Package: openjpeg2 (Red Hat Enterprise Linux 7) - Out of support scope
Package: gimp:flatpak/openjpeg2 (Red Hat Enterprise Linux 8) - Fix deferred
Package: inkscape:flatpak/openjpeg2 (Red Hat Enterprise Linux 8) - Fix deferred
Package: libreoffice:flatpa
Debian
CVE-2023-39327: openjpeg2 - A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the pro...
vendor_debian·2023·CVSS 4.3
CVE-2023-39327 [MEDIUM] CVE-2023-39327: openjpeg2 - A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the pro...
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
ghostscript vulnerabilities
osv·2025-07-08·CVSS 4.3
CVE-2023-39327 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 16.04 LT
GHSA
GHSA-f7p4-6cq7-whmw: A flaw was found in OpenJPEG
ghsa_unreviewed·2024-07-13
CVE-2023-39327 [MEDIUM] CWE-400 GHSA-f7p4-6cq7-whmw: A flaw was found in OpenJPEG
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
OSV
CVE-2023-39327: A flaw was found in OpenJPEG
osv·2024-07-13·CVSS 4.3
CVE-2023-39327 [MEDIUM] CVE-2023-39327: A flaw was found in OpenJPEG
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-13
Published