MEDIUM
openjpeg: out-of-bounds memory read flaws in version 1.5.1
Published Apr 27, 2014
5.0
MEDIUMCVSS 2.0
EPSS 2.17%
Description
OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
openjpeg
Not affected
Red Hat Enterprise Linux 7
openjpeg
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openjpeg | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openjpeg | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not Vulnerable. This issue does not affect the version of openjpeg as shipped with Red Hat Enterprise Linux 6.
Weaknesses (1)
References (8)
- http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS x_refsource_CONFIRMVendor Advisory
- http://seclists.org/oss-sec/2013/q4/412 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/64121 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-6053 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1036493 x_refsource_MISCIssue Tracking
- https://code.google.com/p/openjpeg/issues/detail?id=297 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2013-6053
- https://www.cve.org/CVERecord?id=CVE-2013-6053
| Link | Providers | Tags |
|---|---|---|
| http://openjpeg.googlecode.com/svn/tags/version.1.5.2/NEWS | x_refsource_CONFIRMVendor Advisory | |
| http://seclists.org/oss-sec/2013/q4/412 | mailing-listx_refsource_MLIST | |
| http://www.securityfocus.com/bid/64121 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2013-6053 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1036493 | x_refsource_MISCIssue Tracking | |
| https://code.google.com/p/openjpeg/issues/detail?id=297 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-6053 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-6053 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 27, 2014
Updated Aug 6, 2024
Reserved Oct 8, 2013
Link CVE-2013-6053
CISA Vulnrichment
Updated n/a