Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 18.04 LTS: 5952-1 Moderate Vulnerability in OpenJPEG Code

ubuntu
Calendar Grey March 15, 2023
Scroller Ubuntu
Ubuntu 18.04 and 16.04 receive important patches for OpenJPEG vulnerabilities. Major fixes tackle potential code execution threats.
Several security issues were fixed in OpenJPEG.

Summary

Several security issues were fixed in OpenJPEG.

Software Description:

- openjpeg2: JPEG 2000 image compression/decompression library

Details:

Sebastian Poeplau discovered that OpenJPEG incorrectly handled certain

inputs.

If a user or an automated system were tricked into opening a specially

crafted

input file, a remote attacker could possibly use this issue to cause a

denial

of service or execute arbitrary code. This issue only affected Ubuntu 18.04

LTS. (CVE-2020-6851, CVE-2020-8112)

It was discovered that OpenJPEG incorrectly handled certain inputs. If a

user

or an automated system were tricked into opening a specially crafted input

file, a remote attacker could possibly use this issue to cause a denial of

service or execute arbitrary code. This issue only affected Ubuntu 18.04

LTS.

(CVE-2020-15389, CVE-2020-27814, CVE-2020-27823, CVE-2020-27824,

CVE-2020-27841, CVE-2020-27845)

It was discovered that OpenJPEG incorrectly handled certain inputs....

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
   libopenjp2-7                    2.3.0-2+deb10u2build0.18.04.1
   libopenjp3d7                    2.3.0-2+deb10u2build0.18.04.1
   libopenjpip7                    2.3.0-2+deb10u2build0.18.04.1

Ubuntu 16.04 ESM:
   libopenjp2-7                    2.1.2-1.1+deb9u6ubuntu0.1~esm3
   libopenjp3d7                    2.1.2-1.1+deb9u6ubuntu0.1~esm3
   libopenjpip7                    2.1.2-1.1+deb9u6ubuntu0.1~esm3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5952-1

CVE-2020-15389, CVE-2020-27814, CVE-2020-27823, CVE-2020-27824,

CVE-2020-27841, CVE-2020-27842, CVE-2020-27843, CVE-2020-27845,

CVE-2020-6851, CVE-2020-8112

Severity
important
Lowest
Low
Medium
High
Critical

March 15, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.