Heap-Based Buffer Overflow in OpenJPEG Affects Multiple Versions
CVE-2017-14039

8.8HIGH

Key Information:

Vendor

Uclouvain

Status
Vendor
CVE Published:
30 August 2017

What is CVE-2017-14039?

A heap-based buffer overflow was identified in the opj_t2_encode_packet function in OpenJPEG version 2.2.0. This vulnerability can result in an out-of-bounds write, potentially allowing attackers to cause a remote denial of service or other unspecified impacts. Security advisories have been issued by various organizations, highlighting the urgency to address this issue to protect systems from potential exploitation.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.