Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27814

Опубликовано: 23 нояб. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegNot affected
Red Hat Enterprise Linux 7openjpegNot affected
Red Hat Enterprise Linux 7openjpeg2Will not fix
Red Hat Enterprise Linux 8openjpeg2FixedRHSA-2021:425109.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1901998openjpeg: heap-buffer-overflow in lib/openjp2/mqc.c could result in DoS

EPSS

Процентиль: 49%
0.00255
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

CVSS3: 7.8
nvd
больше 4 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

CVSS3: 7.8
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
больше 4 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain ...

CVSS3: 7.8
github
около 3 лет назад

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

EPSS

Процентиль: 49%
0.00255
Низкий

7.8 High

CVSS3