CVE-2021-3575

HIGH

OpenJPEG < 2.4.0 - Heap-Based Buffer Overflow in sycc420_to_rgb

Title source: llm
STIX 2.1

Description

A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.

References (6)

Core 6
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1957616
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/uclouvain/openjpeg/issues/1347
Third Party Advisory x_refsource_misc
https://ubuntu.com/security/CVE-2021-3575

Scores

CVSS v3 7.8
EPSS 0.0033
EPSS Percentile 56.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (6)
fedoraproject/fedora 33
fedoraproject/fedora 34
redhat/enterprise_linux 6.0
redhat/enterprise_linux 7.0
redhat/enterprise_linux 8.0
uclouvain/openjpeg < 2.4.0
Published Mar 04, 2022
Tracked Since Feb 18, 2026