« List of all CVEs

CVE-2022-1122

Published: 3/29/2022 Last updated: 8/2/2024 Reserved: 3/28/2022

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

grib

Products affected (1)

Product Vendor Version
openjpeg2 n/a 3.12.4S

References (12)