Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-6851

Опубликовано: 13 янв. 2020
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

A heap-based buffer overflow flaw was found in openjpeg in the opj_t1_clbl_decode_processor in libopenjp2.so. Affecting versions through 2.3.1, the highest threat from this vulnerability is to file confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegNot affected
Red Hat Enterprise Linux 7openjpegNot affected
Red Hat Enterprise Linux 7openjpeg2FixedRHSA-2020:026228.01.2020
Red Hat Enterprise Linux 8openjpeg2FixedRHSA-2020:027429.01.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionsopenjpeg2FixedRHSA-2020:029630.01.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1790511openjpeg: Heap-based buffer overflow in opj_t1_clbl_decode_processor()

EPSS

Процентиль: 79%
0.0122
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

CVSS3: 7.5
nvd
около 6 лет назад

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

CVSS3: 7.5
debian
около 6 лет назад

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl ...

CVSS3: 7.5
github
больше 3 лет назад

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in libopenjp2.so.

oracle-oval
около 6 лет назад

ELSA-2020-0274: openjpeg2 security update (IMPORTANT)

EPSS

Процентиль: 79%
0.0122
Низкий

8.1 High

CVSS3

Уязвимость CVE-2020-6851