VDB
BDU%3A2025-03457
BDU%3A2025-03457
PUBLISHED
CVSS 5.199999809265137 MEDIUM
Уязвимость библиотеки для кодирования и декодирования изображений OpenJPEG, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
5.199999809265137
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Red Hat Inc., АО «ИВК», ООО «НЦПР» | openSUSE Tumbleweed, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Red Hat Enterprise Linux, АЛЬТ СП 10, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Module for Package Hub, OpenSUSE Leap, OpenJPEG, МСВСфера |
Timeline
- Mar 27, 2025 CVE Published
- Feb 16, 2026 CVE Updated
References
- https://redos.red-soft.ru/support/secure/ url
- https://www.suse.com/security/cve/CVE-2024-56826.html url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:7309?lang=ru url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://access.redhat.com/security/cve/cve-2024-56826 advisory
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 advisory
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-1113SE18 advisory
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 advisory
- https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8_x0001_ url
- https://github.com/uclouvain/openjpeg/issues/1563 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://security-tracker.debian.org/tracker/CVE-2024-56826 advisory