Back to search
CVE-2021-3575
Published: Mar 4, 2022
Modified: Nov 3, 2025
PUBLISHED
Description
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
| Vendor | Product | Versions |
|---|---|---|
n/a | OpenJPEG | affected Afeects v2.4.0 and prior. |
Weaknesses (CWE)
References
FEDORA-2021-c1ac2ee5ee
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-e145f477df
vendor-advisory
x_refsource_FEDORA
https://bugzilla.redhat.com/show_bug.cgi?id=1957616
x_refsource_MISC
https://github.com/uclouvain/openjpeg/issues/1347
x_refsource_MISC
https://ubuntu.com/security/CVE-2021-3575
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now