OpenJPEG is an open-source JPEG 2000 codec written in C language. It has been developed in order to promote the use of JPEG 2000, a still-image compression standard from the Joint Photographic Experts Group (JPEG). Since April 2015, it is officially recognized by ISO/IEC and ITU-T as a JPEG 2000 Reference Software.
Security Fix(es):
There is a flaw in the opj2compress program in openjpeg2. An attacker who is able to submit a large number of image files to be processed in a directory by opj2compress, could trigger a heap out-of-bounds write due to an integer overflow, which is caused by the large number of image files. The greatest threat posed by this flaw is to confidentiality, integrity, and availability.(CVE-2021-29338)
{ "severity": "Medium" }
{ "x86_64": [ "openjpeg2-2.3.1-7.oe1.x86_64.rpm", "openjpeg2-debugsource-2.3.1-7.oe1.x86_64.rpm", "openjpeg2-debuginfo-2.3.1-7.oe1.x86_64.rpm", "openjpeg2-devel-2.3.1-7.oe1.x86_64.rpm" ], "noarch": [ "openjpeg2-help-2.3.1-7.oe1.noarch.rpm" ], "src": [ "openjpeg2-2.3.1-7.oe1.src.rpm" ], "aarch64": [ "openjpeg2-2.3.1-7.oe1.aarch64.rpm", "openjpeg2-debugsource-2.3.1-7.oe1.aarch64.rpm", "openjpeg2-debuginfo-2.3.1-7.oe1.aarch64.rpm", "openjpeg2-devel-2.3.1-7.oe1.aarch64.rpm" ] }
{ "x86_64": [ "openjpeg2-debugsource-2.3.1-7.oe1.x86_64.rpm", "openjpeg2-2.3.1-7.oe1.x86_64.rpm", "openjpeg2-debuginfo-2.3.1-7.oe1.x86_64.rpm", "openjpeg2-devel-2.3.1-7.oe1.x86_64.rpm" ], "noarch": [ "openjpeg2-help-2.3.1-7.oe1.noarch.rpm" ], "src": [ "openjpeg2-2.3.1-7.oe1.src.rpm" ], "aarch64": [ "openjpeg2-debugsource-2.3.1-7.oe1.aarch64.rpm", "openjpeg2-devel-2.3.1-7.oe1.aarch64.rpm", "openjpeg2-2.3.1-7.oe1.aarch64.rpm", "openjpeg2-debuginfo-2.3.1-7.oe1.aarch64.rpm" ] }