Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27824

Опубликовано: 25 нояб. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegOut of support scope
Red Hat Enterprise Linux 7openjpegOut of support scope
Red Hat Enterprise Linux 7openjpeg2Out of support scope
Red Hat Enterprise Linux 8openjpeg2FixedRHSA-2021:425109.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-120->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1905723openjpeg: global-buffer-overflow read in opj_dwt_calc_explicit_stepsizes()

EPSS

Процентиль: 36%
0.00149
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
nvd
около 4 лет назад

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 5.5
debian
около 4 лет назад

A flaw was found in OpenJPEG\u2019s encoder in the opj_dwt_calc_explic ...

CVSS3: 5.5
github
около 3 лет назад

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

EPSS

Процентиль: 36%
0.00149
Низкий

5.5 Medium

CVSS3