Description: | Summary: The remote host is missing an update for the 'openjpeg' package(s) announced via the USN-5664-1 advisory.
Vulnerability Insight: It was discovered that OpenJPEG did not properly handle PNM headers, resulting in a null pointer dereference. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2016-7445)
It was discovered that OpenJPEG incorrectly handled certain image files resulting in division by zero. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2016-9112 and CVE-2016-10506)
It was discovered that OpenJPEG incorrectly handled converting certain image files resulting in a stack buffer overflow. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2017-17479)
It was discovered that OpenJPEG incorrectly handled converting PNM image files resulting in a null pointer dereference. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2018-18088)
It was discovered that OpenJPEG incorrectly handled converting DWT images files resulting in a buffer overflow. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2020-27824)
Affected Software/OS: 'openjpeg' package(s) on Ubuntu 16.04.
Solution: Please install the updated package(s).
CVSS Score: 7.5
CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
|