{"id":"MGASA-2014-0005","summary":"Updated openjpeg package fixes security vulnerabilities","details":"Multiple heap-based buffer overflow flaws were found in OpenJPEG.\nAn attacker could create a specially crafted OpenJPEG image that, when\nopened, could cause an application using openjpeg to crash or, possibly,\nexecute arbitrary code with the privileges of the user running the\napplication (CVE-2013-6045).\n\nMultiple denial of service flaws were found in OpenJPEG. An attacker could\ncreate a specially crafted OpenJPEG image that, when opened, could cause\nan application using openjpeg to crash (CVE-2013-1447, CVE-2013-6052,\nCVE-2013-6053, CVE-2013-6887).\n","modified":"2026-04-16T06:23:11.369240047Z","published":"2014-01-06T01:10:03Z","upstream":["CVE-2013-1447","CVE-2013-6045","CVE-2013-6052","CVE-2013-6053","CVE-2013-6887"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0005.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11863"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2013/12/04/6"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2013-1850.html"}],"affected":[{"package":{"name":"openjpeg","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/openjpeg?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.1-3.1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0005.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}