CVE-2020-15389
29.06.2020, 21:15
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.Enginsight
Vendor | Product | Version |
---|---|---|
uclouvain | openjpeg | 𝑥 ≤ 2.3.1 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
oracle | outside_in_technology | 8.5.4 |
oracle | outside_in_technology | 8.5.5 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ghostscript |
| ||||||||||||||||||||||
openjpeg |
| ||||||||||||||||||||||
openjpeg2 |
|
Common Weakness Enumeration
References