PT-2025-31936 · Openjpeg · Openjpeg

Sebras

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-54874

CVSS v4.0
7.5
VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Name of the Vulnerable Software and Affected Versions:

OpenJPEG versions 2.5.3 and earlier

Description:

OpenJPEG is an open-source JPEG 2000 codec. A call to the `opj jp2 read header` function may lead to an out-of-bounds heap memory write when the data stream `p stream` is too short and `p image` is not initialized.

Recommendations:

Update OpenJPEG to a version later than 2.5.3.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54874

Affected Products

Openjpeg