CVE-2024-56827
published 2025-01-09CVE-2024-56827: A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress…
PriorityP421medium5.6CVSS 3.1
AVLACLPRLUIRSUCLINAH
EPSS
0.23%
13.9th percentile
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.12 | 9.55.0~dfsg1-0ubuntu5.12 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.7 | 10.02.1~dfsg1-0ubuntu7.7 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 | 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 | 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.15+esm1 | 9.50~dfsg-5ubuntu4.15+esm1 |
| debian | openjpeg2 | < openjpeg2 2.5.0-2+deb12u1 (bookworm) | openjpeg2 2.5.0-2+deb12u1 (bookworm) |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.4.0-3+deb11u1 | 2.4.0-3+deb11u1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-2+deb12u1 | 2.5.0-2+deb12u1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.3-1 | 2.5.3-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.3-1 | 2.5.3-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.1-1ubuntu4.20.04.4 | 2.3.1-1ubuntu4.20.04.4 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.4.0-6ubuntu0.3 | 2.4.0-6ubuntu0.3 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-2ubuntu0.3 | 2.5.0-2ubuntu0.3 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1.1+deb9u6ubuntu0.1~esm7 | 2.1.2-1.1+deb9u6ubuntu0.1~esm7 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2+deb10u2ubuntu0.1~esm4 | 2.3.0-2+deb10u2ubuntu0.1~esm4 |
CVSS provenance
nvdv3.15.6MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ghostscript vulnerabilities
osv·2025-07-08·CVSS 4.3
CVE-2023-39327 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 16.04 LT
OSV
openjpeg2 vulnerabilities
osv·2025-01-22·CVSS 5.6
CVE-2024-56826 [MEDIUM] openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
Frank Zeng discovered that OpenJPEG incorrectly handled memory when using
the decompression utility. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2024-56826,
CVE-2024-56827)
OSV
CVE-2024-56827: A flaw was found in the OpenJPEG project
osv·2025-01-09·CVSS 5.6
CVE-2024-56827 [MEDIUM] CVE-2024-56827: A flaw was found in the OpenJPEG project
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
GHSA
GHSA-jq5v-29wx-7grq: A flaw was found in the OpenJPEG project
ghsa_unreviewed·2025-01-09
CVE-2024-56827 [MEDIUM] CWE-122 GHSA-jq5v-29wx-7grq: A flaw was found in the OpenJPEG project
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 4.3
CVE-2025-27835 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue
Ubuntu
OpenJPEG vulnerabilities
vendor_ubuntu·2025-01-22·CVSS 5.6
CVE-2024-56826 [MEDIUM] OpenJPEG vulnerabilities
Title: OpenJPEG vulnerabilities
Summary: OpenJPEG could be made to crash or run programs if it opened a specially
crafted file.
Frank Zeng discovered that OpenJPEG incorrectly handled memory when using
the decompression utility. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2024-56826,
CVE-2024-56827)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openjpeg: heap buffer overflow in lib/openjp2/j2k.c
vendor_redhat·2024-12-24·CVSS 5.6
CVE-2024-56827 [MEDIUM] CWE-122 openjpeg: heap buffer overflow in lib/openjp2/j2k.c
openjpeg: heap buffer overflow in lib/openjp2/j2k.c
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
Package: openjpeg2 (Red Hat Enterprise Linux 10) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 6) - Out of support scope
Package: openjpeg (Red Hat Enterprise Linux 7) - Out of support scope
Package: openjpeg2 (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2024-56827: openjpeg2 - A flaw was found in the OpenJPEG project. A heap buffer overflow condition may b...
vendor_debian·2024·CVSS 5.6
CVE-2024-56827 [MEDIUM] CVE-2024-56827: openjpeg2 - A flaw was found in the OpenJPEG project. A heap buffer overflow condition may b...
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
Scope: local
bookworm: resolved (fixed in 2.5.0-2+deb12u1)
bullseye: resolved (fixed in 2.4.0-3+deb11u1)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2025:7309https://access.redhat.com/security/cve/CVE-2024-56827https://bugzilla.redhat.com/show_bug.cgi?id=2335174https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8https://github.com/uclouvain/openjpeg/issues/1564https://lists.debian.org/debian-lts-announce/2025/04/msg00002.html
2025-01-09
Published