PT-2021-7871 · Openjpeg2+11 · Openjpeg2+11

Xiaoxiaoafeifei

·

Published

2021-07-13

·

Updated

2025-04-02

·

CVE-2022-1122

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openjpeg2 version 2.4.0
Description A flaw was found in the opj2 decompress program in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Recommendations For openjpeg2 version 2.4.0, consider updating to a newer version that addresses this issue, as the current version may lead to a denial of service when handling a large number of files in an input directory. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Access of Uninitialized Pointer

Improper Initialization

Weakness Enumeration

Related Identifiers

ALSA-2022:7645
ALSA-2022:8207
ALT-PU-2022-1865
ALT-PU-2022-1892
AZL-45240
BDU:2023-03838
CESA-2022_7645
CVE-2022-1122
DLA-2975-1
DLA-4107-1
INFSA-2022_8207
MGASA-2022-0129
OESA-2022-1678
OPENSUSE-SU-2022_1252-1
OPENSUSE-SU-2024:13571-1
RHSA-2022:7645
RHSA-2022:8207
RHSA-2022_7645
RHSA-2022_8207
RLSA-2022:7645
RLSA-2022:8207
ROSA-SA-2024-2537
SUSE-SU-2022:1129-1
SUSE-SU-2022:1252-1
USN-7083-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Openjpeg2