Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Mageia 7, 8: MGASA-2021-0292 Moderate: Openjpeg Buffer Overflow

mageia
Calendar Grey June 28, 2021
Dist Mageia Esm H88
Recent updates to openjpeg2 packages from the Mageia repositories resolve a serious security vulnerability associated with buffer overflow issues.
A heap-based buffer overflow was found in openjpeg

Summary

A heap-based buffer overflow was found in openjpeg. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg (CVE-2021-3575).

References

- https://bugs.mageia.org/show_bug.cgi?id=29127

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BCRXAQJZ7774QPW344OO7IBQX5PPDZ7O/

- https://www.cve.org/CVERecord?id=CVE-2021-3575

Resolution

SRPMS

- 8/core/openjpeg2-2.4.0-1.2.mga8

- 7/core/openjpeg2-2.4.0-1.2.mga7

Publication date: 28 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0292.html
Type: security
CVE: CVE-2021-3575

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here