Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7648

Опубликовано: 02 мар. 2018
Источник: debian
EPSS Низкий

Описание

An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openjpeg2fixed2.3.1-1package

Примечания

  • https://github.com/uclouvain/openjpeg/commit/cc3824767bde397fedb8a1ae4786a222ba860c8d

  • https://github.com/uclouvain/openjpeg/issues/1088

  • The Debian package is built with -DBUILD_MJ2:BOOL=OFF

EPSS

Процентиль: 68%
0.00562
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.

CVSS3: 9.8
nvd
почти 8 лет назад

An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.

EPSS

Процентиль: 68%
0.00562
Низкий