yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2023-39327
Component Overview
Vulnerability Overview
Name
CVE-2023-39327
Source
NVD (
link
)
Debian (
link
)
Description
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
CWEs
CWE-400
Published Date
Jul 13, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://access.redhat.com/security/cve/CVE-2023-39327
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2295812
Issue Tracking
https://access.redhat.com/security/cve/CVE-2023-39327
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2295812
Issue Tracking
Analysis
#
Affected Component
Analysis
openjpeg
Patched
Vulnerability Ratings
#
4.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
openjpeg
buildroot
2025.02.x
2.5.4
Not Affected
openjpeg
buildroot
master
2.5.4
Not Affected
openjpeg
yocto
kirkstone
2.4.0
Patched
openjpeg
yocto
master
2.5.4
Not Affected
Resolved with patches
#
openjpeg (yocto:kirkstone)
#
Title
Author
Resolve
1
fix: when EPH markers are specified, they are required.
mayeut <mayeut@users.noreply.github.com>
CVE-2023-39327
openjpeg (yocto:scarthgap)
#
Title
Author
Resolve
1
CVE-2023-39327
Gyorgy Sarvari <skandigraun@gmail.com>
CVE-2023-39327