Integer Overflow Vulnerability in OpenJPEG Affects UCLouvain's Version
CVE-2021-29338

5.5MEDIUM

Key Information:

Vendor

Uclouvain

Status
Vendor
CVE Published:
14 April 2021

What is CVE-2021-29338?

An Integer Overflow vulnerability exists in OpenJPEG version 2.4.0 that can be exploited by remote attackers to induce a Denial of Service (DoS) condition. This vulnerability can be triggered when an attacker utilizes the command line option '-ImgDir' on a directory containing a large number of files, specifically 1,048,576 files. Successfully exploiting this flaw leads to the crashing of the application, which can disrupt service availability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.