PT-2019-5741 · Openjpeg+8 · Openjpeg+8

Published

2019-06-26

·

Updated

2024-06-15

·

CVE-2019-12973

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenJPEG version 2.3.1
Description The issue is related to excessive iteration in the opj t1 encode cblks function of openjp2/t1.c. Remote attackers could leverage this to cause a denial of service via a crafted bmp file.
Recommendations For OpenJPEG version 2.3.1, consider disabling the opj t1 encode cblks function as a temporary workaround until a patch is available. Restrict access to handling crafted bmp files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4251
ALT-PU-2020-3564
BDU:2021-01280
CESA-2021_4251
CVE-2019-12973
DLA-2277-1
MGASA-2019-0365
OESA-2022-1600
OPENSUSE-SU-2019:2222-1
OPENSUSE-SU-2019:2223-1
OPENSUSE-SU-2019_2222-1
OPENSUSE-SU-2019_2223-1
OPENSUSE-SU-2024:10783-1
OPENSUSE-SU-2024:11120-1
RHSA-2021:4251
RHSA-2021_4251
RLSA-2021:4251
SUSE-SU-2019:2460-1
SUSE-SU-2019:2478-1
USN-4497-1
USN-4782-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Openjpeg
Red Hat
Rocky Linux
Suse
Ubuntu