rpm package
suse/openjpeg2&distro=SUSE Linux Enterprise Server 12 SP3
pkg:rpm/suse/openjpeg2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3
Vulnerabilities (10)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-17480 | Cri | 9.8 | < 2.1.0-4.9.1 | 2.1.0-4.9.1 | Dec 8, 2017 | In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution. | |
| CVE-2017-17479 | Cri | 9.8 | < 2.1.0-4.9.1 | 2.1.0-4.9.1 | Dec 8, 2017 | In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution. | |
| CVE-2015-1239 | Med | 6.5 | < 2.1.0-4.9.1 | 2.1.0-4.9.1 | Oct 18, 2017 | Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF. | |
| CVE-2017-14164 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Sep 6, 2017 | A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possib | |
| CVE-2017-14041 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution. | |
| CVE-2017-14040 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact. | |
| CVE-2017-14039 | Hig | 8.8 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact. | |
| CVE-2016-10507 | Med | 6.5 | < 2.1.0-4.6.1 | 2.1.0-4.6.1 | Aug 30, 2017 | Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file. | |
| CVE-2016-7163 | Hig | 7.8 | < 2.1.0-4.3.2 | 2.1.0-4.3.2 | Sep 21, 2016 | Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. | |
| CVE-2015-8871 | Cri | 9.8 | < 2.1.0-4.3.2 | 2.1.0-4.3.2 | Sep 21, 2016 | Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors. |
- affected < 2.1.0-4.9.1fixed 2.1.0-4.9.1
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
- affected < 2.1.0-4.9.1fixed 2.1.0-4.9.1
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
- affected < 2.1.0-4.9.1fixed 2.1.0-4.9.1
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possib
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.
- affected < 2.1.0-4.6.1fixed 2.1.0-4.6.1
Integer overflow vulnerability in the bmp24toimage function in convertbmp.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted bmp file.
- affected < 2.1.0-4.3.2fixed 2.1.0-4.3.2
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
- affected < 2.1.0-4.3.2fixed 2.1.0-4.3.2
Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.