uclouvain openjpeg
cpe:2.3:a:openjpeg:openjpeg:*:*:*:*:*:*:*, +1 more
- 2.5.2
A heap buffer overflow vulnerability has been identified in the OpenJPEG project, specifically in version 2.5.2 of the opj_decompress utility. This vulnerability can be triggered by certain options, leading to an application crash or other undefined behavior. The issue arises in the 'bin/common/color.c' file, within the 'sycc422_to_rgb' function, when the '-r' option is used with an argument of '2'.
Exploitation of this vulnerability causes a heap buffer overflow, which can lead to memory corruption, application crashes, or potentially allow for arbitrary code execution.
The vulnerability can be reproduced by using the opj_decompress utility with the '-r' option set to '2'. This can be done after compiling OpenJPEG with AddressSanitizer enabled, which will help to detect the heap buffer overflow. The issue can be observed in the 'bin/common/color.c' file, at line 215.
Users can update to the patched version of OpenJPEG available through the Red Hat Enterprise Linux 9 repositories.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.