PT-2020-5601 · Openjpeg+3 · Openjpeg+3

Published

2020-12-14

·

Updated

2024-06-15

·

CVE-2020-27844

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openjpeg versions prior to 2.4.0
Description A flaw was found in openjpeg's src/lib/openjp2/t2.c, allowing an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this issue is to confidentiality, integrity, as well as system availability. This is due to insufficient input validation in the function.
Recommendations For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable t2.c function in src/lib/openjp2/ until a patch is available. Avoid using crafted input for conversion and encoding to minimize the risk of exploitation.

Exploit

Fix

Heap Based Buffer Overflow

Memory Corruption

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3564
ALT-PU-2021-1460
ALT-PU-2021-1511
ALT-PU-2021-1668
ALT-PU-2021-1751
ALT-PU-2021-2141
AZL-44178
BDU:2021-01236
CVE-2020-27844
DLA-2550-1
MGASA-2021-0093
MGASA-2021-0142
OPENSUSE-SU-2021:0392-1
OPENSUSE-SU-2021:0401-1
OPENSUSE-SU-2021_0392-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome
Suse
Openjpeg