Access of Uninitialized Pointer in OpenJPEG - CVE-2022-1122
Published: May 19, 2022 / Updated: December 27, 2024
Vulnerability identifier: #VU63450
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1122
CWE-ID: CWE-824
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to an invalid pointer initialization in the opj2_decompress program. A remote attacker can gain unauthorized access to sensitive information and perform a denial of service attack.
Affected software
OpenJPEG
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Oracle Outside In Technology
SUSE Linux Enterprise Module for Packagehub Subpackages
libopenjp2-7 (Ubuntu package)
libopenjpip7 (Ubuntu package)
libopenjp3d7 (Ubuntu package)
libopenjp2-7
libopenjp2-7-debuginfo
openjpeg2-debuginfo
openjpeg2-debugsource
libopenjp2-7-32bit-debuginfo
libopenjp2-7-32bit
openjpeg2-devel
openjpeg2
openjpeg2-help
mingw-openjpeg2
openjpeg2 (Red Hat package)
media-libs/openjpeg
Oracle AutoVue
IBM FileNet Content Manager
Gentoo Linux
Oracle Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Oracle Outside In Technology
SUSE Linux Enterprise Module for Packagehub Subpackages
libopenjp2-7 (Ubuntu package)
libopenjpip7 (Ubuntu package)
libopenjp3d7 (Ubuntu package)
libopenjp2-7
libopenjp2-7-debuginfo
openjpeg2-debuginfo
openjpeg2-debugsource
libopenjp2-7-32bit-debuginfo
libopenjp2-7-32bit
openjpeg2-devel
openjpeg2
openjpeg2-help
mingw-openjpeg2
openjpeg2 (Red Hat package)
media-libs/openjpeg
Oracle AutoVue
IBM FileNet Content Manager
How to mitigate CVE-2022-1122
Install update from vendor's website.
OpenJPEG - update to 2.5.0
OpenShift API for Data Protection (OADP) - update to 1.1.2
Migration Toolkit for Containers - update to 1.7.6
libopenjp2-7 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.1-1ubuntu4.20.04.3, 2.4.0-6ubuntu0.2, 2.5.0-2ubuntu0.2, 2.5.0-2ubuntu1.1
libopenjpip7 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.1-1ubuntu4.20.04.3, 2.4.0-6ubuntu0.2, 2.5.0-2ubuntu0.2, 2.5.0-2ubuntu1.1
libopenjp3d7 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.1-1ubuntu4.20.04.3, 2.4.0-6ubuntu0.2
libopenjp2-7 - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
libopenjp2-7-debuginfo - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
openjpeg2-debuginfo - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
openjpeg2-debugsource - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
libopenjp2-7-32bit-debuginfo - update to 2.3.0-150000.3.5.1
libopenjp2-7-32bit - update to 2.3.0-150000.3.5.1
openjpeg2-devel - update to 2.3.0-150000.3.5.1
openjpeg2 - update to 2.3.0-150000.3.5.1
openjpeg2 - update to 2.3.1-11
openjpeg2-debuginfo - update to 2.3.1-11
openjpeg2-debugsource - update to 2.3.1-11
openjpeg2-devel - update to 2.3.1-11
openjpeg2-help - update to 2.3.1-11
mingw-openjpeg2 - addressed in versions 2.4.0-4.fc34, 2.4.0-5.fc35
openjpeg2 - addressed in versions 2.4.0-4.fc34, 2.4.0-5.fc35, 2.4.0-10.fc36
openjpeg2 (Red Hat package) - addressed in versions 2.4.0-5.el8, 2.4.0-7.el9
openjpeg2 - update to 2.4.0-11
media-libs/openjpeg - update to 2.5.0
IBM FileNet Content Manager - addressed in versions 5.5.4.0 IF0010, 5.5.8.0 IF004, 5.5.9.0 IF002, 5.5.10.0 IF001
OpenShift API for Data Protection (OADP) - update to 1.1.2
Migration Toolkit for Containers - update to 1.7.6
libopenjp2-7 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.1-1ubuntu4.20.04.3, 2.4.0-6ubuntu0.2, 2.5.0-2ubuntu0.2, 2.5.0-2ubuntu1.1
libopenjpip7 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.1-1ubuntu4.20.04.3, 2.4.0-6ubuntu0.2, 2.5.0-2ubuntu0.2, 2.5.0-2ubuntu1.1
libopenjp3d7 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.3.1-1ubuntu4.20.04.3, 2.4.0-6ubuntu0.2
libopenjp2-7 - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
libopenjp2-7-debuginfo - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
openjpeg2-debuginfo - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
openjpeg2-debugsource - addressed in versions 2.1.0-4.15.1, 2.3.0-150000.3.5.1
libopenjp2-7-32bit-debuginfo - update to 2.3.0-150000.3.5.1
libopenjp2-7-32bit - update to 2.3.0-150000.3.5.1
openjpeg2-devel - update to 2.3.0-150000.3.5.1
openjpeg2 - update to 2.3.0-150000.3.5.1
openjpeg2 - update to 2.3.1-11
openjpeg2-debuginfo - update to 2.3.1-11
openjpeg2-debugsource - update to 2.3.1-11
openjpeg2-devel - update to 2.3.1-11
openjpeg2-help - update to 2.3.1-11
mingw-openjpeg2 - addressed in versions 2.4.0-4.fc34, 2.4.0-5.fc35
openjpeg2 - addressed in versions 2.4.0-4.fc34, 2.4.0-5.fc35, 2.4.0-10.fc36
openjpeg2 (Red Hat package) - addressed in versions 2.4.0-5.el8, 2.4.0-7.el9
openjpeg2 - update to 2.4.0-11
media-libs/openjpeg - update to 2.5.0
IBM FileNet Content Manager - addressed in versions 5.5.4.0 IF0010, 5.5.8.0 IF004, 5.5.9.0 IF002, 5.5.10.0 IF001
External References
- https://github.com/uclouvain/openjpeg/issues/1368
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ROSN5NRUFOH7HGLJ4ZSKPGAKLFXJALW4/
- https://lists.debian.org/debian-lts-announce/2022/04/msg00006.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIWSQFQWXDU4MT3XTVAO6HC7TVL3NHS7/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RMKBAMK2CAM5TMC5TODKVCE5AAPTD5YV/
Related Security Bulletins
- Denial of service in OpenJPEG
- Gentoo update for OpenJPEG
- Red Hat Enterprise Linux 8 update for openjpeg2
- Red Hat Enterprise Linux 9 update for openjpeg2
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in Oracle Outside In Technology
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.1
- SUSE update for openjpeg2
- SUSE update for openjpeg2
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in IBM FileNet Content Manager
- Multiple vulnerabilities in Oracle AutoVue
- Multiple vulnerabilities in Oracle Linux
- openEuler update for openjpeg2
- Amazon Linux AMI update for openjpeg2
- Ubuntu update for openjpeg2
- Fedora 36 update for openjpeg2
- Fedora 35 update for mingw-openjpeg2, openjpeg2
- Fedora 34 update for mingw-openjpeg2, openjpeg2