CVE-2018-20847: Integer Overflow
An improper computation of ptx0, ptx1, pty0 and pty1 in the function opjgetencodingparameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20847?
CVE-2018-20847 is a vulnerability that involves an improper computation in the OpenJPEG library, which can lead to an integer overflow.
What is the severity of CVE-2018-20847?
CVE-2018-20847 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2018-20847?
OpenJPEG versions up to and including 2.3.0 are affected by CVE-2018-20847.
How can I fix CVE-2018-20847?
To fix CVE-2018-20847, it is recommended to update to OpenJPEG version 2.3.1 or later.
Where can I find more information about CVE-2018-20847?
You can find more information about CVE-2018-20847 at the following references: [CVE-2018-20847](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20847), [OpenJPEG Commit](https://github.com/uclouvain/openjpeg/commit/5d00b719f4b93b1445e6fb4c766b9a9883c57949), [OpenJPEG Issues](https://github.com/uclouvain/openjpeg/issues/431).