A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | RedHat | openjpeg2-0:2.4.0-8.el9 | * |
| Blender | Ubuntu | esm-apps/xenial | * |
| Blender | Ubuntu | focal | * |
| Blender | Ubuntu | oracular | * |
| Blender | Ubuntu | plucky | * |
| Ghostscript | Ubuntu | esm-infra-legacy/xenial | * |
| Ghostscript | Ubuntu | esm-infra/bionic | * |
| Ghostscript | Ubuntu | esm-infra/xenial | * |
| Insighttoolkit4 | Ubuntu | esm-apps/xenial | * |
| Insighttoolkit4 | Ubuntu | focal | * |
| Openjpeg2 | Ubuntu | devel | * |
| Openjpeg2 | Ubuntu | esm-apps-legacy/xenial | * |
| Openjpeg2 | Ubuntu | esm-apps/bionic | * |
| Openjpeg2 | Ubuntu | esm-apps/xenial | * |
| Openjpeg2 | Ubuntu | esm-infra/focal | * |
| Openjpeg2 | Ubuntu | focal | * |
| Openjpeg2 | Ubuntu | jammy | * |
| Openjpeg2 | Ubuntu | noble | * |
| Openjpeg2 | Ubuntu | oracular | * |
| Openjpeg2 | Ubuntu | plucky | * |
| Openjpeg2 | Ubuntu | questing | * |
| Openjpeg2 | Ubuntu | resolute | * |
| Openjpeg2 | Ubuntu | upstream | * |
| Qtwebengine-opensource-src | Ubuntu | focal | * |
| Qtwebengine-opensource-src | Ubuntu | oracular | * |
| Qtwebengine-opensource-src | Ubuntu | plucky | * |
| Texmaker | Ubuntu | esm-apps/xenial | * |
| Texmaker | Ubuntu | focal | * |
| Texmaker | Ubuntu | oracular | * |
| Texmaker | Ubuntu | plucky | * |