PT-2021-8086 · Openjpeg+9 · Openjpeg+9

Yuawn

·

Published

2021-04-30

·

Updated

2026-05-26

·

CVE-2021-3575

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenJPEG (affected versions not specified)
Description The issue is related to a heap-based buffer overflow in the color.c component of the OpenJPEG library, specifically in the sycc420 to rgb function. This can be exploited by a remote attacker using a specially crafted .j2k file, potentially allowing access to confidential data, disruption of data integrity, and denial of service. The vulnerability also enables an attacker to execute arbitrary code with the permissions of the application compiled against OpenJPEG.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4251
ALT-PU-2022-1865
ALT-PU-2022-1892
ALT-PU-2024-3037
AZL-44643
BDU:2024-06926
CESA-2021_4251
CVE-2021-3575
DLA-4107-1
DSA-5851-1
JLSEC-2026-546
MGASA-2021-0292
OESA-2022-1600
OPENSUSE-SU-2024:13748-1
RHSA-2021:4251
RHSA-2021_4251
RLSA-2021:4251
USN-7083-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Openjpeg
Red Hat
Rocky Linux
Ubuntu