Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 433766 (CVE-2012-3535) - <media-libs/openjpeg-1.5.1: JPEG2000 Image Processing Buffer Overflow Vulnerability (CVE-2012-3535)
Summary: <media-libs/openjpeg-1.5.1: JPEG2000 Image Processing Buffer Overflow Vulnera...
Alias: CVE-2012-3535
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Whiteboard: B2 [glsa]
Depends on: 472536
  Show dependency tree
Reported: 2012-09-03 10:28 UTC by Agostino Sarubbo
Modified: 2013-10-10 11:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-09-03 10:28:55 UTC
A vulnerability has been reported in OpenJPEG, which can be exploited by malicious people to potentially compromise an application using the library.

The vulnerability is caused due to an error when decoding images and can be exploited to cause a heap-based buffer overflow via a specially crafted file.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in version 1.5.0. Other versions may also be affected.

No official solution is currently available.
Comment 1 Agostino Sarubbo gentoo-dev 2012-09-03 10:29:37 UTC
Note: this is not CVE-2012-3358 ( bug 425772 )
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2012-09-08 15:44:27 UTC
CVE-2012-3535 (
  Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote
  attackers to cause a denial of service (application crash) and possibly
  execute arbitrary code via a crafted JPEG2000 file.
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2013-09-29 15:22:11 UTC
GLSA request filed.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2013-10-10 11:49:02 UTC
This issue was resolved and addressed in
 GLSA 201310-07 at
by GLSA coordinator Sean Amoss (ackle).