OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
References
Link | Resource |
---|---|
https://github.com/uclouvain/openjpeg/commit/f809b80c67717c152a5ad30bf06774f00da4fd2d | Patch |
https://github.com/uclouvain/openjpeg/pull/1573 | Third Party Advisory |
https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV | Exploit Third Party Advisory |
Configurations
History
26 Sep 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized. |
12 Sep 2025, 17:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:* | |
Summary |
|
|
References | () https://github.com/uclouvain/openjpeg/commit/f809b80c67717c152a5ad30bf06774f00da4fd2d - Patch | |
References | () https://github.com/uclouvain/openjpeg/pull/1573 - Third Party Advisory | |
References | () https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV - Exploit, Third Party Advisory | |
First Time |
Uclouvain openjpeg
Uclouvain |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
05 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-05 15:15
Updated : 2025-09-26 22:15
NVD link : CVE-2025-54874
Mitre link : CVE-2025-54874
CVE.ORG link : CVE-2025-54874
JSON object : View
Products Affected
uclouvain
- openjpeg
CWE
CWE-457
Use of Uninitialized Variable