PT-2013-1171 · Centos+4 · Centos+4

Published

2013-12-12

·

Updated

2021-02-02

·

CVE-2013-6054

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openjpeg versions prior to 1.5.2 openjpeg-1.3 openjpeg-debuginfo-1.3 openjpeg-devel-1.3 openjpeg-libs-1.3
Description The issue affects the openjpeg package in various operating systems, including CentOS, Gentoo Linux, and Red Hat Enterprise Linux. It involves multiple vulnerabilities that can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. One of the vulnerabilities is a heap-based buffer overflow in OpenJPEG 1.3.
Recommendations For openjpeg versions prior to 1.5.2, update to version 1.5.2 or later. For openjpeg-1.3, openjpeg-debuginfo-1.3, openjpeg-devel-1.3, and openjpeg-libs-1.3, consider disabling the vulnerable components until a patch is available. As a temporary workaround, restrict access to the vulnerable modules to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2337
ALT-PU-2021-1097
ALT-PU-2021-1197
BDU:2015-06455
BDU:2015-06456
BDU:2015-06457
BDU:2015-06458
BDU:2015-08985
BDU:2015-08986
BDU:2015-08987
BDU:2015-08988
BDU:2015-09772
CESA-2013_1850
CVE-2013-6054
DSA-2808-1
RHSA-2013:1850
RHSA-2013_1850

Affected Products

Alt Linux
Centos
Gentoo Linux
Openjpeg
Red Hat