ECHO-6358-d799-1471

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-6358-d799-1471.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-6358-d799-1471
Upstream
Withdrawn
2025-11-17T16:30:08Z
Published
2025-09-15T01:09:13Z
Modified
2026-09-15T03:33:35Z
Summary
The vulnerability is in the mj2 component, which is not built because debian build with the -DBUILD_MJ2:BOOL=OFF flag. https://github.com/uclouvain/openjpeg/issues/1127 https://security-tracker.debian.org/tracker/CVE-2018-16376
Details
References

Affected packages

Echo / openjpeg2

Package

Name
openjpeg2
Purl
pkg:deb/echo/openjpeg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.5.3-2.1~deb13u1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-6358-d799-1471.json"