[CLSA-2026:1777979854] openjpeg: Fix of CVE-2018-21010
Type:
security
Severity:
Important
Release date:
2026-05-05 11:17:39 UTC
Description:
- CVE-2018-21010: heap buffer overflow in color_apply_icc_profile when RGB components have differing widths or heights; reject such inputs after cleaning up the LCMS transform handle and profiles.
Updated packages:
  • openjpeg-1.5.1-19.amzn2.tuxcare.els1.x86_64.rpm
    sha:fdc36312d4ea8c05f3cd09801d435b1373e588b1d632677d041f215c47976eaf
  • openjpeg-devel-1.5.1-19.amzn2.tuxcare.els1.x86_64.rpm
    sha:3e8c64384a38dc43b3f7371fe2e775f5019882fd88b3b53038c480c9877a5271
  • openjpeg-libs-1.5.1-19.amzn2.tuxcare.els1.i686.rpm
    sha:e4d86d2f28b14f93c4c176ea3464350fd271afa1b3d52d42eb9b6d20c89eb584
  • openjpeg-libs-1.5.1-19.amzn2.tuxcare.els1.x86_64.rpm
    sha:48f51cc9b535f3a230b5273466930c955520132249177b768ed8c64177301fc1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.