CVE-2023-39327

NameCVE-2023-39327
DescriptionA flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5851-1
Debian Bugs1081908

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openjpeg2 (PTS)bullseye2.4.0-3vulnerable
bookworm2.5.0-2vulnerable
bookworm (security)2.5.0-2+deb12u1fixed
sid, trixie2.5.3-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openjpeg2sourcebookworm2.5.0-2+deb12u1DSA-5851-1
openjpeg2source(unstable)(unfixed)1081908

Notes

[bullseye] - openjpeg2 <no-dsa> (Minor issue)
https://github.com/uclouvain/openjpeg/issues/1472
Partial mitigation of CVE-2023-39327 (in absence of EPH):
https://github.com/uclouvain/openjpeg/commit/822562d689f491ae5d012627ba00ac235d399b9e (v2.5.3)

Search for package or bug name: Reporting problems