Denial of Service Vulnerability in OpenJPEG by UCLouvain
CVE-2019-6988

6.5MEDIUM

Key Information:

Vendor

Uclouvain

Status
Vendor
CVE Published:
28 January 2019

What is CVE-2019-6988?

In OpenJPEG 2.3.0, a vulnerability exists that allows remote attackers to initiate a denial of service condition. This is triggered by excessive memory allocation requests within the opj_calloc function, which can be exploited through a maliciously prepared input file. The vulnerability occurs when opj_calloc is invoked from the opj_tcd_init_tile function, potentially leading to significant application disruption.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.