exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp
Published Jul 26, 2021
8.1
HIGHCVSS 3.1
EPSS 0.24%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of CVE-2021-29457. Notes: All CVE users should reference CVE-2021-29457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 7
compat-exiv2-023-0:0.23-2.el7_9
Fixed · RHSA-2021:3234
Red Hat Enterprise Linux 7
compat-exiv2-026-0:0.26-3.el7_9
Fixed · RHSA-2021:3233
Red Hat Enterprise Linux 7
exiv2-0:0.27.0-4.el7_8
Fixed · RHSA-2021:3158
Red Hat Enterprise Linux 8
compat-exiv2-026-0:0.26-4.el8_4
Fixed · RHSA-2021:3153
Red Hat Enterprise Linux 8
exiv2-0:0.27.3-3.el8_4
Fixed · RHSA-2021:3152
Red Hat Enterprise Linux 8.1 Extended Update Support
exiv2-0:0.26-11.el8_1
Fixed · RHSA-2021:3232
Red Hat Enterprise Linux 8.2 Extended Update Support
compat-exiv2-026-0:0.26-4.el8_2
Fixed · RHSA-2021:3230
Red Hat Enterprise Linux 8.2 Extended Update Support
exiv2-0:0.27.2-6.el8_2
Fixed · RHSA-2021:3231
Red Hat Enterprise Linux 6
exiv2
Out of support scope
Red Hat Enterprise Linux 9
exiv2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | compat-exiv2-023-0:0.23-2.el7_9 | Fixed | RHSA-2021:3234 |
| Red Hat Enterprise Linux 7 | compat-exiv2-026-0:0.26-3.el7_9 | Fixed | RHSA-2021:3233 |
| Red Hat Enterprise Linux 7 | exiv2-0:0.27.0-4.el7_8 | Fixed | RHSA-2021:3158 |
| Red Hat Enterprise Linux 8 | compat-exiv2-026-0:0.26-4.el8_4 | Fixed | RHSA-2021:3153 |
| Red Hat Enterprise Linux 8 | exiv2-0:0.27.3-3.el8_4 | Fixed | RHSA-2021:3152 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | exiv2-0:0.26-11.el8_1 | Fixed | RHSA-2021:3232 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | compat-exiv2-026-0:0.26-4.el8_2 | Fixed | RHSA-2021:3230 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | exiv2-0:0.27.2-6.el8_2 | Fixed | RHSA-2021:3231 |
| Red Hat Enterprise Linux 6 | exiv2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | exiv2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2021-31291 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1990327 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-18202 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-31291
- https://www.cve.org/CVERecord?id=CVE-2021-31291
Change history (0)
No recorded changes yet.
CISA Vulnrichment
No data
GitHub
No data