UBUNTU-CVE-2020-15389
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-15389
UBUNTU-CVE-2020-15389
Summary:
Details: jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
References: https://ubuntu.com/security/CVE-2020-15389, https://pastebin.com/4sDKQ7U8, https://ubuntu.com/security/notices/USN-4685-1, https://ubuntu.com/security/notices/USN-4497-1, https://ubuntu.com/security/notices/USN-5952-1, https://www.cve.org/CVERecord?id=CVE-2020-15389
Affected packages
Package
Name: openjpeg2
Purl: pkg:deb/ubuntu/[email protected]+deb9u5build0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
