cbcvebase.

Debian Openjpeg2 vulnerabilities

64 known vulnerabilities affecting debian/openjpeg2.

Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH20MEDIUM27LOW15

Vulnerabilities

Page 3 of 4
CVE-2018-5785P4LOWCVSS 6.5fixed in openjpeg2 2.3.0-2 (bookworm)2018
CVE-2018-5785 [MEDIUM] CVE-2018-5785: openjpeg2 - In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left ... In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. Scope: local bookworm: resolved (fixed in 2.3.0-2) bullseye: resolved (fixed in 2.3.0-2) forky: resolved (fixed in 2.3.0-
debian
CVE-2018-18088P4LOWCVSS 6.5fixed in openjpeg2 2.3.0-2 (bookworm)2018
CVE-2018-18088 [MEDIUM] CVE-2018-18088: openjpeg2 - OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm functi... OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c Scope: local bookworm: resolved (fixed in 2.3.0-2) bullseye: resolved (fixed in 2.3.0-2) forky: resolved (fixed in 2.3.0-2) sid: resolved (fixed in 2.3.0-2) trixie: resolved (fixed in 2.3.0-2)
debian
CVE-2018-5727P4LOWCVSS 6.5fixed in openjpeg2 2.3.1-1 (bookworm)2018
CVE-2018-5727 [MEDIUM] CVE-2018-5727: openjpeg2 - In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_enco... In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1) sid: resolved (fixed in
debian
CVE-2020-27843P4MEDIUMCVSS 5.5fixed in openjpeg2 2.4.0-1 (bookworm)2020
CVE-2020-27843 [MEDIUM] CVE-2020-27843: openjpeg2 - A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an att... A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: reso
debian
CVE-2020-27824P4MEDIUMCVSS 5.5fixed in openjpeg2 2.4.0-1 (bookworm)2020
CVE-2020-27824 [MEDIUM] CVE-2020-27824: openjpeg2 - A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() ... A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky
debian
CVE-2016-10506P4LOWCVSS 6.5fixed in openjpeg2 2.2.0-1 (bookworm)2016
CVE-2016-10506 [MEDIUM] CVE-2016-10506: openjpeg2 - Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_... Division-by-zero vulnerabilities in the functions opj_pi_next_cprl, opj_pi_next_pcrl, and opj_pi_next_rpcl in pi.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files. Scope: local bookworm: resolved (fixed in 2.2.0-1) bullseye: resolved (fixed in 2.2.0-1) forky: resolved (fixed in 2.2.0-1) sid:
debian
CVE-2015-1239P4MEDIUMCVSS 6.5fixed in openjpeg2 2.1.1-1 (bookworm)2015
CVE-2015-1239 [MEDIUM] CVE-2015-1239: openjpeg2 - Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r29... Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF. Scope: local bookworm: resolved (fixed in 2.1.1-1) bullseye: resolved (fixed in 2.1.1-1) forky: resolved (fixed in 2.1.1-1) sid: resolved (fixed in 2.1.1-1) t
debian
CVE-2016-3183P4LOWCVSS 5.5fixed in openjpeg2 2.1.1-1 (bookworm)2016
CVE-2016-3183 [MEDIUM] CVE-2016-3183: openjpeg2 - The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows rem... The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file. Scope: local bookworm: resolved (fixed in 2.1.1-1) bullseye: resolved (fixed in 2.1.1-1) forky: resolved (fixed in 2.1.1-1) sid: resolved (fixed in 2.1.1-1) trixie: resolved (fixed in 2.1.1-1)
debian
CVE-2021-29338P4MEDIUMCVSS 5.5fixed in openjpeg2 2.4.0-4 (bookworm)2021
CVE-2021-29338 [MEDIUM] CVE-2021-29338: openjpeg2 - Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the applica... Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files. Scope: local bookworm: resolved (fixed in 2.4.0-4) bullseye: resolved (fixed in 2.4.0-3+deb11u1) forky: resolved (fixed in 2.4.0-4
debian
CVE-2018-20845P4LOWCVSS 6.5fixed in openjpeg2 2.3.1-1 (bookworm)2018
CVE-2018-20845 [MEDIUM] CVE-2018-20845: openjpeg2 - Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, an... Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash). Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1) sid: resolved (fixed in 2.3.1-
debian
CVE-2018-20846P4LOWCVSS 6.5fixed in openjpeg2 2.3.1-1 (bookworm)2018
CVE-2018-20846 [MEDIUM] CVE-2018-20846: openjpeg2 - Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl... Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash). Scope: local bookworm: resolved (fixed in 2.3.1-1) bullseye: resolved (fixed in 2.3.1-1) forky: resolved (fixed in 2.3.1-1
debian
CVE-2017-12982P4LOWCVSS 5.5fixed in openjpeg2 2.3.0-1 (bookworm)2017
CVE-2017-12982 [MEDIUM] CVE-2017-12982: openjpeg2 - The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does... The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c. Scope: local bookworm: resolved (fi
debian
CVE-2020-27845P4MEDIUMCVSS 5.5fixed in openjpeg2 2.4.0-1 (bookworm)2020
CVE-2020-27845 [MEDIUM] CVE-2020-27845: openjpeg2 - There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. I... There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw is to application availability. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.
debian
CVE-2020-27841P4MEDIUMCVSS 5.5fixed in openjpeg2 2.4.0-1 (bookworm)2020
CVE-2020-27841 [MEDIUM] CVE-2020-27841: openjpeg2 - There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. W... There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1
debian
CVE-2014-7947P4MEDIUMCVSS 5.0fixed in openjpeg2 2.1.1-1 (bookworm)2014
CVE-2014-7947 [MEDIUM] CVE-2014-7947: openjpeg2 - OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, a... OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c. Scope: local bookworm: resolved (fixed in 2.1.1-1) bullseye: resolved (fixed in 2.1.1-1) forky: resolved (fixed in 2.1.1-1) sid: re
debian
CVE-2020-27842P4MEDIUMCVSS 5.5fixed in openjpeg2 2.4.0-1 (bookworm)2020
CVE-2020-27842 [MEDIUM] CVE-2020-27842: openjpeg2 - There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker ... There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in
debian
CVE-2024-56826P4MEDIUMCVSS 5.6fixed in openjpeg2 2.5.0-2+deb12u1 (bookworm)2024
CVE-2024-56826 [MEDIUM] CVE-2024-56826: openjpeg2 - A flaw was found in the OpenJPEG project. A heap buffer overflow condition may b... A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior. Scope: local bookworm: resolved (fixed in 2.5.0-2+deb12u1) bullseye: resolved (fixed in 2.4.0-3+deb11u1) forky: resolved (fixed in
debian
CVE-2024-56827P4MEDIUMCVSS 5.6fixed in openjpeg2 2.5.0-2+deb12u1 (bookworm)2024
CVE-2024-56827 [MEDIUM] CVE-2024-56827: openjpeg2 - A flaw was found in the OpenJPEG project. A heap buffer overflow condition may b... A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior. Scope: local bookworm: resolved (fixed in 2.5.0-2+deb12u1) bullseye: resolved (fixed in 2.4.0-3+deb11u1) forky: resolved (fixed in
debian
CVE-2019-12973P4MEDIUMCVSS 5.5fixed in openjpeg2 2.4.0-1 (bookworm)2019
CVE-2019-12973 [MEDIUM] CVE-2019-12973: openjpeg2 - In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks funct... In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616. Scope: local bookworm: resolved (fixed in 2.4.0-1) bullseye: resolved (fixed in 2.4.0-1) forky: resolved (fixed in 2.4.
debian
CVE-2022-1122P4MEDIUMCVSS 5.5fixed in openjpeg2 2.5.0-1 (bookworm)2022
CVE-2022-1122 [MEDIUM] CVE-2022-1122: openjpeg2 - A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it... A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service. Scope: local bookworm: resolved (fixed in 2.
debian
Debian Openjpeg2 vulnerabilities | cvebase