Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-29338

Опубликовано: 24 мар. 2021
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

There is a flaw in the opj2_compress program in openjpeg2. An attacker who is able to submit a large number of image files to be processed in a directory by opj2_compress, could trigger a heap out-of-bounds write due to an integer overflow, which is caused by the large number of image files. The greatest threat posed by this flaw is to confidentiality, integrity, and availability.

Отчет

This flaw affects the opj2_compress utility but is not in the openjpeg2 library. Therefore, the attack vector is local to the opj2_compress utility and would require an attacker to convince a user to open a directory with an extremely large number of files using opj2_compress, or a script to be feeding such arbitrary, untrusted files to opj2_compress.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegOut of support scope
Red Hat Enterprise Linux 7openjpegOut of support scope
Red Hat Enterprise Linux 7openjpeg2Out of support scope
Red Hat Enterprise Linux 8gimp:flatpak/openjpeg2Fix deferred
Red Hat Enterprise Linux 8inkscape:flatpak/openjpeg2Fix deferred
Red Hat Enterprise Linux 9openjpeg2Not affected
Red Hat Enterprise Linux 8openjpeg2FixedRHSA-2021:425109.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1950101openjpeg: out-of-bounds write due to an integer overflow in opj_compress.c

EPSS

Процентиль: 27%
0.00092
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 4 лет назад

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

CVSS3: 5.5
nvd
около 4 лет назад

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

CVSS3: 5.5
debian
около 4 лет назад

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash t ...

CVSS3: 5.5
github
около 3 лет назад

Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость параметра командной строки -ImgDir библиотеки для кодирования и декодирования изображений OpenJPEG, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00092
Низкий

6.2 Medium

CVSS3