CVE-2019-6988 PUBLISHED

An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.

EPSS 0.33% · 55.4th percentile

Risk Scores

EPSS Score
0.33%
55.4th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSopenjpeg20, 2.4.0-6ubuntu0.4, 2.4.0-6ubuntu0.3
Ubuntu:24.04:LTSopenjpeg22.5.0-2build2, 0, 2.5.0-2ubuntu0.1
Ubuntu:25.10openjpeg22.5.3-2.1, 2.5.3-2, 0
Ubuntu:Pro:20.04:LTSopenjpeg22.3.0-2, 2.3.1-1ubuntu4.20.04.4+esm1, 2.3.1-1ubuntu4.20.04.4
Ubuntu:Pro:18.04:LTSghostscript9.26~dfsg+0-0ubuntu0.18.04.18+esm2, 0, 9.21~dfsg+1-0ubuntu3
Ubuntu:Pro:16.04:LTSghostscript9.26~dfsg+0-0ubuntu0.16.04.7, 9.26~dfsg+0-0ubuntu0.16.04.5, 9.26~dfsg+0-0ubuntu0.16.04.4
Ubuntu:Pro:18.04:LTSopenjpeg22.3.0-2+deb10u2ubuntu0.1~esm2, 2.3.0-2+deb10u2ubuntu0.1~esm3, 2.3.0-2+deb10u2ubuntu0.1~esm4
Ubuntu:Pro:16.04:LTSopenjpeg22.1.2-1.1+deb9u6ubuntu0.1~esm1, 2.1.2-1.1+deb9u6ubuntu0.1~esm3, 2.1.2-1.1+deb9u6ubuntu0.1~esm6

Timeline

References

Open in Interactive Console →