MGASA-2020-0307

Source
https://advisories.mageia.org/MGASA-2020-0307.html
Import Source
https://advisories.mageia.org/MGASA-2020-0307.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0307
Related
Published
2020-07-31T23:25:42Z
Modified
2020-07-31T22:43:33Z
Summary
Updated openjpeg2 packages fix security vulnerability
Details

jp2/opjdecompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opjimage_destroy twice (CVE-2020-15389).

References
Credits

Affected packages