Use-after-free in Debian Linux - CVE-2015-8871
Published: September 21, 2016 / Updated: August 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing unknown vectors. A remote attackers can have unspecified impact.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Gentoo Linux
Fedora
Opensuse
SUSE Package Hub for SUSE Linux Enterprise
media-libs/openjpeg
openjpeg2
mingw-openjpeg2
How to mitigate CVE-2015-8871
openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24
mingw-openjpeg2 - addressed in versions 2.1.1-1.fc23, 2.1.1-1.fc24
External References
- http://www.debian.org/security/2016/dsa-3665
- http://www.openwall.com/lists/oss-security/2015/09/15/4
- http://www.openwall.com/lists/oss-security/2016/05/13/1
- http://www.securitytracker.com/id/1038623
- https://bugzilla.redhat.com/show_bug.cgi?id=1263359
- https://github.com/uclouvain/openjpeg/blob/master/CHANGELOG.md
- https://github.com/uclouvain/openjpeg/commit/940100c28ae28931722290794889cf84a92c5f6f
- https://github.com/uclouvain/openjpeg/issues/563
- https://security.gentoo.org/glsa/201612-26