Note:
This project will be discontinued after December 13, 2021. [more]
2017-12-08
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
Products | Ubuntu_linux, Debian_linux, Openjpeg |
Type | Out-of-bounds Write (CWE-787) |
First patch | - None (likely due to unavailable code) |
Links |
• https://usn.ubuntu.com/4109-1/
• https://www.debian.org/security/2019/dsa-4405 • https://github.com/uclouvain/openjpeg/issues/1044 • https://lists.debian.org/debian-lts-announce/2018/11/msg00018.html |