Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Use After Free jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
Remediation
There is no fixed version for openjpeg2
.
References
CVSS Score
6.5
medium severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2020-15389
- CWE
- CWE-416
- Snyk ID
- SNYK-DEBIAN10-OPENJPEG2-574801
- Disclosed
- 29 Jun, 2020
- Published
- 30 Jun, 2020