CVE-2017-12982: Buffer Overflow
Last updated 24 July 2024
Other sources
The bmpreadinfoheader function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opjimagecreate function in lib/openjp2/image.c, related to the opjalignedallocn function in opjmalloc.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12982?
The severity of CVE-2017-12982 is medium with a severity value of 5.5.
How does CVE-2017-12982 affect OpenJPEG versions?
CVE-2017-12982 affects OpenJPEG versions 2.2.0 up to, but not including, 2.3.0.
How can remote attackers exploit CVE-2017-12982?
Remote attackers can exploit CVE-2017-12982 by sending specially crafted headers with a zero biBitCount.
What is the remedy for CVE-2017-12982 in Ubuntu?
The remedy for CVE-2017-12982 in Ubuntu is to update OpenJPEG to version 2.3.0.
Where can I find more information about CVE-2017-12982?
You can find more information about CVE-2017-12982 in the references section of the vulnerability description.