Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
created 2 months ago
OpenJPEG allows OOB heap memory write in opj_jp2_read_header

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

Affected products

openjpeg
  • ==>= 2.5.1, <= 2.5.3
  • ==<= 2.5.3

Matching in nixpkgs

Package maintainers