Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: MGASA-2021-0100 High: Openjpeg Buffer Overflow Threat

mageia
Calendar Grey March 2, 2021
Dist Mageia Esm H88
Newly released openjpeg2 updates for Mageia address a vital security vulnerability that safeguards the confidentiality and integrity of sensitive information.
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0

Summary

A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. (CVE-2020-27844).

References

- https://bugs.mageia.org/show_bug.cgi?id=27986

- https://lists.debian.org/debian-lts-announce/2021/02/msg00011.html

- https://www.cve.org/CVERecord?id=CVE-2020-27844

Resolution

SRPMS

- 7/core/openjpeg2-2.4.0-1.mga7

Publication date: 02 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0093.html
Type: security
CVE: CVE-2020-27844

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here