Heap-based Buffer Overflow in OpenJPEG Image Decoder
CVE-2014-0158

8.8HIGH

Key Information:

Vendor

Uclouvain

Status
Vendor
CVE Published:
10 April 2018

What is CVE-2014-0158?

A heap-based buffer overflow vulnerability exists in the JPEG2000 image tile decoder used in OpenJPEG versions prior to 1.5.2. This vulnerability allows remote attackers to craft specific malicious files that can cause denial of service by crashing the application. The issue arises from improper interactions during the j2k_decode, j2k_read_eoc, and tcd_decode_tile processes. It is closely related to previous vulnerabilities, indicating a need for vigilant security practices and timely updates to mitigate risks associated with image handling.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.