Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8112

Опубликовано: 07 фев. 2020
Источник: redhat
CVSS3: 8.8

Описание

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

A heap-based buffer overflow flaw was found in the opj_t1_clbl_decode_processor in openjpeg2. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegNot affected
Red Hat Enterprise Linux 7openjpegNot affected
Red Hat Enterprise Linux 7openjpeg2FixedRHSA-2020:055019.02.2020
Red Hat Enterprise Linux 8openjpeg2FixedRHSA-2020:057024.02.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutionsopenjpeg2FixedRHSA-2020:056924.02.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1800535openjpeg: heap-based buffer overflow in pj_t1_clbl_decode_processor in openjp2/t1.c

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

CVSS3: 8.8
nvd
около 6 лет назад

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

CVSS3: 8.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 8.8
debian
около 6 лет назад

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through ...

github
больше 3 лет назад

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

8.8 High

CVSS3