PT-2020-6590 · Openjpeg+9 · Openjpeg+9
Published
2020-12-01
·
Updated
2023-03-15
·
CVE-2020-27842
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
openjpeg versions prior to 2.4.0
Description
The issue is related to a flaw in openjpeg's t2 encoder, which can cause a null pointer dereference when crafted input is processed. This can lead to application availability issues. The flaw is associated with reading beyond the valid boundaries of a data buffer. An attacker who can provide specially designed input to be processed by openjpeg could exploit this issue, potentially causing a denial of service.
Recommendations
For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the input to the t2 encoder to prevent crafted input from being processed.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Openjpeg