QID 198299

Date Published: 2021-03-31

QID 198299: Ubuntu Security Notification for Openjpeg2 Vulnerabilities (USN-4880-1)

It was discovered that OpenJPEG incorrectly handled certain image data.

An attacker could use this issue to cause OpenJPEG to crash, leading to a denial of service, or possibly execute arbitrary code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Ubuntu advisory USN-4880-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-4880-1 16.04 (Xenial) on src libopenjp2-7 URL Logo launchpad.net/ubuntu/+source/openjpeg2/2.1.2-1.1+deb9u6build0.16.04.1
    USN-4880-1 16.04 (Xenial) on src libopenjp3d7 URL Logo launchpad.net/ubuntu/+source/openjpeg2/2.1.2-1.1+deb9u6build0.16.04.1
    USN-4880-1 16.04 (Xenial) on src libopenjpip7 URL Logo launchpad.net/ubuntu/+source/openjpeg2/2.1.2-1.1+deb9u6build0.16.04.1