In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openjpeg | Jan 2, 2019 | Feb 4, 2018 |
| Debian | — | Upgrade openjpeg2 | Feb 20, 2019 | Feb 4, 2018 |
| Freebsd | — | Upgrade openjpeg | Jul 28, 2018 | Jul 27, 2018 |
| Oracle Solaris | — | Upgrade image/library/openjpeg2 to version 2.3.1-11.4.11.0.1.2.0 on Solaris 11.4 | Jul 17, 2019 | Feb 4, 2018 |
| Suse | — | Upgrade ghostscript-x11Upgrade ghostscript-develUpgrade ghostscript | Dec 19, 2019 | Feb 4, 2018 |
| Ubuntu | — | Upgrade libopenjp2-7Upgrade libopenjp3d7Upgrade libopenjpip7 | Aug 22, 2019 | Feb 4, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub