Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27823

Опубликовано: 25 нояб. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

Red Hat Product Security has rated this flaw with Moderate severity because it affects the encoder functionality specifically when performing an image conversion and not general reading of image files.

Меры по смягчению последствий

This flaw can be mitigated by not using openjpeg to convert untrusted image files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegOut of support scope
Red Hat Enterprise Linux 7openjpegOut of support scope
Red Hat Enterprise Linux 7openjpeg2Out of support scope
Red Hat Enterprise Linux 8openjpeg2FixedRHSA-2021:425109.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-120->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1905762openjpeg: heap-buffer-overflow write in opj_tcd_dc_level_shift_encode()

EPSS

Процентиль: 10%
0.00037
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
nvd
около 4 лет назад

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 7.8
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
около 4 лет назад

A flaw was found in OpenJPEG\u2019s encoder. This flaw allows an attac ...

github
около 3 лет назад

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

EPSS

Процентиль: 10%
0.00037
Низкий

7.8 High

CVSS3