REDHAT-BUG-2335172: Medium severity openjpeg vulnerability
This bug is triggered when we use opjdecompress with the -r option and its argument set to 2. Version v2.5.2 also has this vulnerability.
Reproducible: Always
Steps to Reproduce: see https://github.com/uclouvain/openjpeg/issues/1563
References: https://github.com/uclouvain/openjpeg/issues/1563 https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8 https://bugzilla.redhat.com/showbug.cgi?id=2333954
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2335172?
The severity of REDHAT-BUG-2335172 is considered critical due to the impact it can have when decompressing images.
How do I fix REDHAT-BUG-2335172?
To fix REDHAT-BUG-2335172, upgrade to a patched version of OpenJPEG that addresses this specific vulnerability.
Which version of OpenJPEG is affected by REDHAT-BUG-2335172?
OpenJPEG version 2.5.2 is specifically affected by REDHAT-BUG-2335172.
What triggers the vulnerability in REDHAT-BUG-2335172?
The vulnerability in REDHAT-BUG-2335172 is triggered when using the opj_decompress command with the -r option set to 2.
Is REDHAT-BUG-2335172 reproducible?
Yes, REDHAT-BUG-2335172 is reproducible under the specified conditions listed in the bug report.