CVE-2020-27824: Buffer Overflow
A flaw was found in OpenJPEG’s encoder in the opjdwtcalcexplicitstepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.
Other sources
In openjpeg v2.3.1 and prior, if too many decomposition levels are supplied to the encoder, it could cause a global buffer overflow to out-of-bounds read in the opjdwtcalcexplicitstepsizes() function.
Reference: https://github.com/uclouvain/openjpeg/issues/1286 Upstream patch: https://github.com/uclouvain/openjpeg/pull/1292/commits/6daf5f3e1ec6eff03b7982889874a3de6617db8d
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27824?
CVE-2020-27824 is a vulnerability found in OpenJPEG's encoder that allows an attacker to cause a buffer overflow by supplying crafted input to decomposition levels.
What is the highest threat from CVE-2020-27824?
The highest threat from CVE-2020-27824 is to system availability.
What is the severity level of CVE-2020-27824?
CVE-2020-27824 has a severity level of medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2020-27824?
OpenJPEG versions 2.3.1-1ubuntu5, 2.3.0-2+, and 2.4.0 are affected by CVE-2020-27824.
Are there any references for CVE-2020-27824?
Yes, you can find references for CVE-2020-27824 at the following links: [link1], [link2].