PT-2020-6590 · Openjpeg+9 · Openjpeg+9

CVE-2020-27842

·

Published

2020-12-01

·

Updated

2023-03-15

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions openjpeg versions prior to 2.4.0
Description The issue is related to a flaw in openjpeg's t2 encoder, which can cause a null pointer dereference when crafted input is processed. This can lead to application availability issues. The flaw is associated with reading beyond the valid boundaries of a data buffer. An attacker who can provide specially designed input to be processed by openjpeg could exploit this issue, potentially causing a denial of service.
Recommendations For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the input to the t2 encoder to prevent crafted input from being processed.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4251
ALT-PU-2020-3564
AZL-44106
BDU:2022-00329
CESA-2021_4251
CVE-2020-27842
DLA-2975-1
DSA-4882-1
MGASA-2020-0478
OESA-2022-1486
OPENSUSE-SU-2022_3802-1
OPENSUSE-SU-2022_4082-1
OPENSUSE-SU-2024:13571-1
RHSA-2021:4251
RHSA-2021_4251
RLSA-2021:4251
SUSE-SU-2022:3801-1
SUSE-SU-2022:3802-1
SUSE-SU-2022:4082-1
USN-4685-1
USN-4686-1
USN-5952-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Openjpeg