OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Tue, 05 Aug 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Uclouvain
Uclouvain openjpeg |
|
Vendors & Products |
Uclouvain
Uclouvain openjpeg |
Tue, 05 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Aug 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized. | |
Title | OpenJPEG allows OOB heap memory write in opj_jp2_read_header | |
Weaknesses | CWE-457 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-05T14:33:17.323Z
Updated: 2025-08-05T14:49:31.036Z
Reserved: 2025-07-31T17:23:33.473Z
Link: CVE-2025-54874

Updated: 2025-08-05T14:48:30.244Z

Status : Awaiting Analysis
Published: 2025-08-05T15:15:32.000
Modified: 2025-08-05T21:06:25.813
Link: CVE-2025-54874
