REDHAT-BUG-2335174: Medium severity openjpeg vulnerability
This bug is triggered when we use opjdecompress with the -t option and its argument set to 1. The latest version v2.5.2 also has this vulnerability.
Reproducible: Always
Steps to Reproduce: see https://github.com/uclouvain/openjpeg/issues/1564
References: https://github.com/uclouvain/openjpeg/issues/1564 https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2335174?
The severity of REDHAT-BUG-2335174 is critical due to the potential for exploitation when using opj_decompress with the -t option.
How do I fix REDHAT-BUG-2335174?
To fix REDHAT-BUG-2335174, update to the latest version of OpenJPEG that addresses this specific bug.
What versions of OpenJPEG are affected by REDHAT-BUG-2335174?
All versions of OpenJPEG up to and including v2.5.2 are affected by REDHAT-BUG-2335174.
What triggers the vulnerability in REDHAT-BUG-2335174?
The vulnerability in REDHAT-BUG-2335174 is triggered when using opj_decompress with the -t option set to 1.
Is there a workaround for REDHAT-BUG-2335174?
There is currently no known workaround for REDHAT-BUG-2335174 other than applying the available updates.