Vulnerability CVE-2013-4289: Information

Description

Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow.

Severity: CRITICAL (10.0)

Published: April 18, 2014
Modified: Sept. 9, 2020
Error type identifier: CWE-189

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libopenjpegp101.5.2-alt11.5.2-alt1ALT-PU-2019-2337-1235157Fixed
libopenjpegp91.5.2-alt11.5.2-alt1ALT-PU-2021-1097-1264567Fixed
libopenjpegc10f11.5.2-alt11.5.2-alt1ALT-PU-2019-2337-1235157Fixed
libopenjpegc9f21.5.2-alt11.5.2-alt1ALT-PU-2021-1197-1264629Fixed
libopenjpeg2.0sisyphus2.5.0-alt12.5.2-alt1ALT-PU-2022-1865-1299926Fixed
libopenjpeg2.0sisyphus_e2k2.5.0-alt12.5.2-alt1ALT-PU-2022-4997-1-Fixed
libopenjpeg2.0sisyphus_riscv642.5.0-alt12.5.2-alt1ALT-PU-2022-4954-1-Fixed
libopenjpeg2.0p102.5.0-alt12.5.0-alt1ALT-PU-2022-1892-1300002Fixed
libopenjpeg2.0p10_e2k2.5.0-alt12.5.0-alt1ALT-PU-2022-4992-1-Fixed
libopenjpeg2.0c10f12.5.0-alt12.5.0-alt1ALT-PU-2022-1892-1300002Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:uclouvain:openjpeg:1.3:*:*:*:*:*:*:*

      cpe:2.3:a:uclouvain:openjpeg:1.4:*:*:*:*:*:*:*

      cpe:2.3:a:uclouvain:openjpeg:1.5:*:*:*:*:*:*:*

      cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*
      End including
      1.5.1