Integer Overflow Vulnerability in OpenJPEG Affects Multiple Versions
CVE-2018-20847

8.8HIGH

Key Information:

Vendor

Uclouvain

Status
Vendor
CVE Published:
26 June 2019

What is CVE-2018-20847?

An integer overflow vulnerability exists in OpenJPEG due to improper computation of p_tx0, p_tx1, p_ty0, and p_ty1 in the function opj_get_encoding_parameters located in openjp2/pi.c. This flaw can be exploited by attackers to manipulate parameters leading to unexpected behaviors and security issues, affecting multiple versions of the software up to and including 2.3.0. Users are encouraged to upgrade to newer versions to mitigate potential risks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.