Bugzilla – Bug 971615
VUL-0: CVE-2016-3182: openjpeg2: Heap corruption in opj_free function
Last modified: 2022-04-01 07:26:44 UTC
rh#1317826 Double free or heap corruption vulnerability was found in opj_free function triggered by specially crafted JPEG2000 image file was found in openjpeg 2016.03.14. References: https://bugzilla.redhat.com/show_bug.cgi?id=1317826 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-3182 http://seclists.org/oss-sec/2016/q1/667
bugbot adjusting priority
Sorry for taking so long to reply... This issue does not affect openjpeg but openjpeg2 (see also rh#1317826). Reassigning to default since I do not maintain openjpeg2.
Upstream bug: https://github.com/uclouvain/openjpeg/issues/726 Upstream fix: https://github.com/uclouvain/openjpeg/commit/15f081c89650dccee4aa4ae66f614c3fdb268767.patch I would propose to upgrade openjpeg to 2.3.0 in leap 42.3 to fix all the issues at once.
Sorry, above comment was intended for another bug. For this one upstream issue is: https://github.com/uclouvain/openjpeg/issues/725 Still an update to 2.3.0 would solve it.
Origin of the issue seems to be the same as for bug 971618 (CVE-2016-3181). I addressed it there. Suggest we close this, but up to maint-coord.
closing.