Vulncode-DB
  • Home
  • About
  • Deprecation
  • News
    Login/Register
  •  
  • Issues 
    File a bug Feature request
  • Slack
  • Twitter
Note:

This project will be discontinued after December 13, 2021. [more]

    CVE-2019-12973 (NVD)

    2019-06-26

    In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

    Products Debian_linux, Leap, Database_server, Outside_in_technology, Openjpeg
    Type Excessive Iteration (CWE-834)
    First patch - None (likely due to unavailable code)
    Patches https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67b11ec3
    Links • https://security.gentoo.org/glsa/202101-29
    • https://www.oracle.com//security-alerts/cpujul2021.html
    • http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.html
    • https://github.com/uclouvain/openjpeg/pull/1185/commits/cbe7384016083eac16078b359acd7a842253d503
    • https://lists.debian.org/debian-lts-announce/2020/07/msg00008.html
    More/Less (3)
    • http://www.securityfocus.com/bid/108900
    • http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.html
    • https://www.oracle.com/security-alerts/cpujul2020.html

    Disclaimer: Vulncode-DB is not an officially supported Google product. Terms of Use
    See the vulncode-db repository for more information.


    Running version: bffd1467df54d98e5271ec977330365d5879b60d (2021-11-29 03:52:21)