Opened 13 months ago

Closed 12 months ago

Last modified 8 months ago

#22175 closed enhancement (fixed)

openjpeg-2.5.4

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version

Change History (6)

comment:1 by zeckma, 13 months ago

Priority: normal → elevated

Fixes CVE-2025-54874, which allows an attacker to write to heap memory via an out of bounds vulnerability, rated as Medium.

comment:2 by zeckma, 13 months ago

Changes

OpenJPEG 2.5.4 (Sept 2025)

No API/ABI break compared to v2.5.3

Bug fixes

  • opj_jp2_read_header: Check for error after parsing header (CVE-2025-54874)
  • pkgconfig: drop unused libraries from Libs.private
  • Fix CMake warning: Compatibility with CMake < 3.10 will be removed
  • Fixed ICC profile copy failure on write

comment:3 by Douglas R. Reno, 13 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:4 by Douglas R. Reno, 12 months ago

Priority: elevated → high

comment:5 by Douglas R. Reno, 12 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at c7d90d8f0acc7c50ec2d8d2a42d19499731bce27

SA-12.4-009 issued

comment:6 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.