CVE-2018-21010
Published: 5 September 2019
OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.
From the Ubuntu Security Team
It was discovered that OpenJPEG did not properly handle certain input. If OpenJPEG were supplied with specially crafted input, it could be made to crash or potentially execute arbitrary code.
Priority
Status
Package | Release | Status |
---|---|---|
qtwebengine-opensource-src Launchpad, Ubuntu, Debian |
groovy |
Ignored
(end of life)
|
hirsute |
Ignored
(end of life)
|
|
kinetic |
Ignored
(end of life, was needs-triage)
|
|
jammy |
Needs triage
|
|
impish |
Ignored
(end of life)
|
|
bionic |
Needs triage
|
|
disco |
Ignored
(end of life)
|
|
eoan |
Ignored
(end of life)
|
|
focal |
Needs triage
|
|
lunar |
Needs triage
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
mantic |
Needs triage
|
|
blender Launchpad, Ubuntu, Debian |
hirsute |
Ignored
(end of life)
|
kinetic |
Ignored
(end of life, was needs-triage)
|
|
xenial |
Needs triage
|
|
jammy |
Needs triage
|
|
bionic |
Needs triage
|
|
disco |
Ignored
(end of life)
|
|
eoan |
Ignored
(end of life)
|
|
focal |
Needs triage
|
|
impish |
Ignored
(end of life)
|
|
groovy |
Ignored
(end of life)
|
|
lunar |
Needs triage
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
mantic |
Needs triage
|
|
gdcm Launchpad, Ubuntu, Debian |
hirsute |
Not vulnerable
(uses system openjpeg)
|
jammy |
Not vulnerable
(uses system openjpeg)
|
|
bionic |
Not vulnerable
(uses system openjpeg)
|
|
disco |
Not vulnerable
(uses system openjpeg)
|
|
eoan |
Not vulnerable
(uses system openjpeg)
|
|
focal |
Not vulnerable
(uses system openjpeg)
|
|
groovy |
Not vulnerable
(uses system openjpeg)
|
|
impish |
Not vulnerable
(uses system openjpeg)
|
|
kinetic |
Not vulnerable
(uses system openjpeg)
|
|
lunar |
Not vulnerable
(uses system openjpeg)
|
|
trusty |
Not vulnerable
(uses system openjpeg)
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(uses system openjpeg)
|
|
mantic |
Not vulnerable
(uses system openjpeg)
|
|
ghostscript Launchpad, Ubuntu, Debian |
focal |
Not vulnerable
(uses system openjpeg2)
|
groovy |
Not vulnerable
(uses system openjpeg2)
|
|
hirsute |
Not vulnerable
(uses system openjpeg2)
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
bionic |
Not vulnerable
(code not compiled)
|
|
xenial |
Not vulnerable
(code not compiled)
|
|
jammy |
Not vulnerable
(uses system openjpeg2)
|
|
impish |
Not vulnerable
(uses system openjpeg2)
|
|
kinetic |
Not vulnerable
(uses system openjpeg2)
|
|
lunar |
Not vulnerable
(uses system openjpeg2)
|
|
mantic |
Not vulnerable
(uses system openjpeg2)
|
|
insighttoolkit4 Launchpad, Ubuntu, Debian |
hirsute |
Ignored
(end of life)
|
kinetic |
Ignored
(end of life, was needs-triage)
|
|
xenial |
Needs triage
|
|
jammy |
Needs triage
|
|
disco |
Ignored
(end of life)
|
|
eoan |
Ignored
(end of life)
|
|
focal |
Needs triage
|
|
impish |
Ignored
(end of life)
|
|
bionic |
Needs triage
|
|
groovy |
Ignored
(end of life)
|
|
lunar |
Needs triage
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
mantic |
Does not exist
|
|
openjpeg Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
upstream |
Needs triage
|
|
jammy |
Does not exist
|
|
trusty |
Ignored
(changes too intrusive)
|
|
impish |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
xenial |
Ignored
(changes too intrusive)
|
|
mantic |
Does not exist
|
|
openjpeg2 Launchpad, Ubuntu, Debian |
hirsute |
Not vulnerable
(2.3.1-1)
|
jammy |
Not vulnerable
(2.3.1-1)
|
|
bionic |
Needed
|
|
disco |
Ignored
(end of life)
|
|
eoan |
Ignored
(end of life)
|
|
focal |
Not vulnerable
(2.3.1-1)
|
|
groovy |
Not vulnerable
(2.3.1-1)
|
|
impish |
Not vulnerable
(2.3.1-1)
|
|
kinetic |
Not vulnerable
(2.3.1-1)
|
|
lunar |
Not vulnerable
(2.3.1-1)
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Released
(2.1.2-1.1+deb9u5build0.16.04.1)
|
|
mantic |
Not vulnerable
(2.3.1-1)
|
|
Patches: upstream: https://github.com/uclouvain/openjpeg/commit/2e5ab1d9987831c981ff05862e8ccf1381ed58ea |
||
texmaker Launchpad, Ubuntu, Debian |
hirsute |
Ignored
(end of life)
|
kinetic |
Ignored
(end of life, was needs-triage)
|
|
xenial |
Needs triage
|
|
jammy |
Needs triage
|
|
impish |
Ignored
(end of life)
|
|
bionic |
Needs triage
|
|
disco |
Ignored
(end of life)
|
|
eoan |
Ignored
(end of life)
|
|
focal |
Needs triage
|
|
groovy |
Ignored
(end of life)
|
|
lunar |
Needs triage
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
mantic |
Needs triage
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.8 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |