Debian Openjpeg2 vulnerabilities
64 known vulnerabilities affecting debian/openjpeg2.
Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH20MEDIUM27LOW15
Vulnerabilities
Page 4 of 4
CVE-2018-6616P4MEDIUMCVSS 5.5fixed in openjpeg2 2.3.0-2 (bookworm)2018
CVE-2018-6616 [MEDIUM] CVE-2018-6616: openjpeg2 - In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks funct...
In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
Scope: local
bookworm: resolved (fixed in 2.3.0-2)
bullseye: resolved (fixed in 2.3.0-2)
forky: resolved (fixed in 2.3.0-2)
sid: resolved (fixed in 2.3.0-2)
trix
debian
CVE-2016-3182P4MEDIUMCVSS 5.5fixed in openjpeg2 2.1.1-1 (bookworm)2016
CVE-2016-3182 [MEDIUM] CVE-2016-3182: openjpeg2 - The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 a...
The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
trixie: resolved (fixed in 2.1.1-1
debian
CVE-2016-1626P4MEDIUMCVSS 4.3fixed in openjpeg2 2.1.2-1.2 (bookworm)2016
CVE-2016-1626 [MEDIUM] CVE-2016-1626: openjpeg2 - The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in ...
The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
Scope: local
bookworm: resolved (fixed in 2.1.2-1.2)
bullseye: resolved (fixed in 2.1.2-1.2)
forky:
debian
CVE-2016-4797P4MEDIUMCVSS 5.0fixed in openjpeg2 2.1.1-1 (bookworm)2016
CVE-2016-4797 [MEDIUM] CVE-2016-4797: openjpeg2 - Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJ...
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
Scope: local
bookworm: resolved (fixed in 2.1.1-1)
bullseye: resolved (fixed in 2.1.1-1)
forky: resol
debian
← Previous4 / 4