Security advisory published on the oss-sec feed on 5 October, attributed to Security @ Red Eagle Tech. According to the text, the OpenJPEG reversible forward 5/3 wavelet transform reads and writes past the end of a heap allocation when the lower resolution levels of a tile have zero height at an odd start. The affected versions are OpenJPEG 2.4.0 to 2.5.4 and the git master branch. The problem is on the encoder side, not the decoder, and is reached through encoding parameters rather than an input file crafted for that purpose. A single encoding usually appears normal; the defect shows up when the same encoding is repeated within one process, as happens in programs that encode more than one image. The available text is a machine translation, and the excerpt gives no fix or fixed-version note. To verify, consult the original advisory in the public oss-sec discussion archive for the fourth quarter of 2026 and confirm the version in use against the OpenJPEG project notes.
Cyber ·
OpenJPEG 2.4.0 to 2.5.4 and git master: heap buffer overflow during encoding
Advisory on a heap buffer overflow in the OpenJPEG encoder, versions 2.4.0 to 2.5.4 and git master, triggered by encoding parameters rather than a crafted input file.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.