vulnerability
Arch Linux: Denial of service (CVE-2020-27824)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:M/Au:N/C:N/I:N/A:P) | May 13, 2021 | Jul 11, 2025 | Nov 27, 2025 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
May 13, 2021
Added
Jul 11, 2025
Modified
Nov 27, 2025
Description
In OpenJPEG before version 2.4.0, if too many decomposition levels are supplied to the encoder, it could cause a global buffer overflow to out-of-bounds read in the opj_dwt_calc_explicit_stepsizes() function.
Solution
arch-linux-upgrade-latest
References
- CVE-2020-27824
- https://attackerkb.com/topics/CVE-2020-27824
- URL-https://bugzilla.redhat.com/show_bug.cgi?id=1905723
- URL-https://lists.debian.org/debian-lts-announce/2021/02/msg00011.html
- URL-https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQR4EWRFFZQDMFPZKFZ6I3USLMW6TKTP/
- URL-https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJUPGIZE6A4O52EBOF75MCXJOL6MUCRV/
- URL-https://security.archlinux.org/ASA-202012-21
- URL-https://www.debian.org/security/2021/dsa-4882
- URL-https://www.oracle.com/security-alerts/cpuoct2021.html
- CWE-20
- CWE-125
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.