Denial of Service Vulnerability in OpenJPEG by UCLouvain
CVE-2019-6988
6.5MEDIUM
What is CVE-2019-6988?
In OpenJPEG 2.3.0, a vulnerability exists that allows remote attackers to initiate a denial of service condition. This is triggered by excessive memory allocation requests within the opj_calloc function, which can be exploited through a maliciously prepared input file. The vulnerability occurs when opj_calloc is invoked from the opj_tcd_init_tile function, potentially leading to significant application disruption.
