PT-2020-5601 · Openjpeg+3 · Openjpeg+3
Published
2020-12-14
·
Updated
2024-06-15
·
CVE-2020-27844
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
openjpeg versions prior to 2.4.0
Description
A flaw was found in openjpeg's src/lib/openjp2/t2.c, allowing an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this issue is to confidentiality, integrity, as well as system availability. This is due to insufficient input validation in the function.
Recommendations
For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable
t2.c function in src/lib/openjp2/ until a patch is available. Avoid using crafted input for conversion and encoding to minimize the risk of exploitation.Exploit
Fix
Heap Based Buffer Overflow
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Suse
Openjpeg