CVE-2021-3575
04.03.2022, 18:15
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.Enginsight
Vendor | Product | Version |
---|---|---|
uclouvain | openjpeg | 𝑥 ≤ 2.4.0 |
redhat | enterprise_linux | 6.0 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
blender |
| ||||||||||||||||||||||||
ghostscript |
| ||||||||||||||||||||||||
insighttoolkit4 |
| ||||||||||||||||||||||||
openjpeg |
| ||||||||||||||||||||||||
openjpeg2 |
| ||||||||||||||||||||||||
qtwebengine-opensource-src |
| ||||||||||||||||||||||||
texmaker |
|
Common Weakness Enumeration
References