[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-MGASA-2017-0122":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":24,"duplicates":25,"related":26,"reserved_at":9,"published_at":32,"modified_at":33,"state":9,"summary":34,"references_raw":36,"kevs":53,"epss":9,"epss_history":54,"metrics":55,"affected":56},"MGASA-2017-0122","Updated openjpeg packages fix security vulnerability\n\nMultiple integer overflows in the opj_tcd_init_tile function in tcd.c in\nOpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow\nremote attackers to cause a denial of service (heap-based buffer overflow)\nor possibly have unspecified other impact via crafted JPEG 2000 data.\n(CVE-2016-5139)\n\nMultiple integer overflows in the opj_tcd_init_tile function in tcd.c in\nOpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on\nWindows and OS X and before 53.0.2785.92 on Linux, allow remote attackers\nto cause a denial of service (heap-based buffer overflow) or possibly have\nunspecified other impact via crafted JPEG 2000 data. (CVE-2016-5158)\n\nMultiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome\nbefore 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux,\nallow remote attackers to cause a denial of service (heap-based buffer\noverflow) or possibly have unspecified other impact via crafted JPEG 2000\ndata that is mishandled during opj_aligned_malloc calls in dwt.c and t1.c.\n(CVE-2016-5159)\n\nInteger overflow in the opj_pi_create_decode function in pi.c in OpenJPEG\nallows remote attackers to execute arbitrary code via a crafted JP2 file,\nwhich triggers an out-of-bounds read or write. (CVE-2016-7163)\n\nAn out-of-bounds read vulnerability was found in OpenJPEG, in the\nj2k_to_image tool. Converting a specially crafted JPEG2000 file to another\nformat could cause the application to crash or, potentially, disclose some\ndata from the heap. (CVE-2016-9573\n",null,[],[],[],[14,16,18,20,22],{"_key":15},"CVE-2016-5139",{"_key":17},"CVE-2016-5158",{"_key":19},"CVE-2016-5159",{"_key":21},"CVE-2016-7163",{"_key":23},"CVE-2016-9573",[],[],[27,28,29,30,31],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},"2017-05-02T06:37:59Z","2026-04-16T06:22:20.374312955Z",{"cisa_kev":35,"cisa_ransomware":35,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[37,43,48],{"url":38,"sources":39,"tags":41},"https://advisories.mageia.org/MGASA-2017-0122.html",[40],"osv_mageia",[42],"Advisory",{"url":44,"sources":45,"tags":46},"https://bugs.mageia.org/show_bug.cgi?id=20559",[40],[47],"REPORT",{"url":49,"sources":50,"tags":51},"https://rhn.redhat.com/errata/RHSA-2017-0838.html",[40],[47,52],"WEB",[],[],[],[57],{"ecosystem":58,"name":59,"vendor":60,"product":59,"cpe_part":9,"purl_type":61,"purl_namespace":60,"purl_name":59,"source":9,"versions":62},"Mageia","openjpeg","mageia","rpm",[63],{"version":64,"is_range":65,"range_type":66,"version_start":9,"version_start_type":9,"version_end":67,"version_end_type":68,"fixed_in":9},"lt1_5_2_5_2_mga5",true,"ecosystem","1.5.2-5.2.mga5","excluding"]