ALAS2-2023-1999

Related Vulnerabilities: CVE-2021-3575  

A heap-based buffer overflow was found in OpenJPEG. This flaw allows an attacker to execute arbitrary code with the permissions of the application compiled against OpenJPEG. (CVE-2021-3575)

ALAS2-2023-1999


Amazon Linux 2 Security Advisory: ALAS-2023-1999
Advisory Release Date: 2023-03-17 16:35 Pacific
Advisory Updated Date: 2023-03-21 23:25 Pacific
Severity: Medium

Issue Overview:

A heap-based buffer overflow was found in OpenJPEG. This flaw allows an attacker to execute arbitrary code with the permissions of the application compiled against OpenJPEG. (CVE-2021-3575)


Affected Packages:

openjpeg


Issue Correction:
Run yum update openjpeg to update your system.

New Packages:
aarch64:
    openjpeg-1.5.1-19.amzn2.aarch64
    openjpeg-libs-1.5.1-19.amzn2.aarch64
    openjpeg-devel-1.5.1-19.amzn2.aarch64
    openjpeg-debuginfo-1.5.1-19.amzn2.aarch64

i686:
    openjpeg-1.5.1-19.amzn2.i686
    openjpeg-libs-1.5.1-19.amzn2.i686
    openjpeg-devel-1.5.1-19.amzn2.i686
    openjpeg-debuginfo-1.5.1-19.amzn2.i686

src:
    openjpeg-1.5.1-19.amzn2.src

x86_64:
    openjpeg-1.5.1-19.amzn2.x86_64
    openjpeg-libs-1.5.1-19.amzn2.x86_64
    openjpeg-devel-1.5.1-19.amzn2.x86_64
    openjpeg-debuginfo-1.5.1-19.amzn2.x86_64