Back

MEDIUM

openjpeg: out-of-bounds write due to an integer overflow in opj_compress.c

Published Apr 14, 2021

Description

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

Affected products

Remediation

Red Hat statement

This flaw affects the opj2_compress utility but is not in the openjpeg2 library. Therefore, the attack vector is local to the opj2_compress utility and would require an attacker to convince a user to open a directory with an extremely large number of files using opj2_compress, or a script to be feeding such arbitrary, untrusted files to opj2_compress.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 14, 2021
Updated Nov 3, 2025
Reserved Mar 29, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 24, 2021