CVE-2020-27841: Buffer Overflow
A flaw was found in OpenJPEG. Specially crafted files can lead to multiple heap-based buffer overflows in lib/openjp2/pi.c.
Reference: https://github.com/uclouvain/openjpeg/issues/1293
Other sources
There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw in openjpeg?
The vulnerability ID of this flaw in openjpeg is CVE-2020-27841.
What is the severity of CVE-2020-27841?
The severity of CVE-2020-27841 is medium with a severity value of 5.5.
Which versions of openjpeg are affected by CVE-2020-27841?
Versions of openjpeg prior to 2.4.0 are affected by CVE-2020-27841.
What is the impact of CVE-2020-27841?
The greatest impact of CVE-2020-27841 is to application availability.
How do I fix CVE-2020-27841 in openjpeg?
To fix CVE-2020-27841, update openjpeg to version 2.4.0 or later.