USN-5664-1
Dashboard / Vulnerabilities / USN-5664-1
USN-5664-1
Summary: openjpeg vulnerabilities
Details: It was discovered that OpenJPEG did not properly handle PNM headers, resulting in a null pointer dereference. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2016-7445) It was discovered that OpenJPEG incorrectly handled certain image files resulting in division by zero. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2016-9112 and CVE-2016-10506) It was discovered that OpenJPEG incorrectly handled converting certain image files resulting in a stack buffer overflow. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2017-17479) It was discovered that OpenJPEG incorrectly handled converting PNM image files resulting in a null pointer dereference. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2018-18088) It was discovered that OpenJPEG incorrectly handled converting DWT images files resulting in a buffer overflow. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2020-27824)
References: https://ubuntu.com/security/notices/USN-5664-1, https://ubuntu.com/security/CVE-2016-7445, https://ubuntu.com/security/CVE-2016-9112, https://ubuntu.com/security/CVE-2016-10506, https://ubuntu.com/security/CVE-2017-17479, https://ubuntu.com/security/CVE-2018-18088, https://ubuntu.com/security/CVE-2020-27824
Affected packages
Package
Name: openjpeg
Purl: pkg:deb/ubuntu/openjpeg?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
