VDB

GCVE-VVD-MAGEIA-2020-307

GCVE-VVD-MAGEIA-2020-307
Advisory Published
Vulnetix · Advisory published July 31, 2020
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice (CVE-2020-15389).

Affected Products

VendorProductVersionsPlatforms
Mageiaopenjpeg20 (affected), 2.3.1-1.4.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›