Heap-based Buffer Overflow in OpenJPEG by UCLouvain
CVE-2018-16375
8.8HIGH
What is CVE-2018-16375?
A vulnerability exists in OpenJPEG version 2.3.0 where the lack of validation checks for header_info.height and header_info.width within the pnmtoimage function in bin/jpwl/convert.c can result in a heap-based buffer overflow. This may allow an attacker to manipulate the application memory, potentially leading to arbitrary code execution or instability of the application. It is crucial for users of OpenJPEG to be aware of this issue and take appropriate measures to mitigate risks.
