CVE-2020-27842: Null Pointer Dereference
A flaw was found in OpenJPEG. Specially crafted file can lead to an out-of-bounds read in opjtgtreset function in lib/openjp2/tgt.c.
Reference: https://github.com/uclouvain/openjpeg/issues/1294
Other sources
OpenJPEG is vulnerable to a denial of service, caused by a NULL pointer dereference in lib/openjp2/tgt.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27842?
CVE-2020-27842 is a vulnerability in openjpeg's t2 encoder in versions prior to 2.4.0.
How does CVE-2020-27842 impact application availability?
The highest impact of CVE-2020-27842 is to application availability.
Which software versions are affected by CVE-2020-27842?
Versions prior to 2.4.0 of openjpeg's t2 encoder are affected by CVE-2020-27842.
Where can I find more information about CVE-2020-27842?
You can find more information about CVE-2020-27842 at the following references: [link1], [link2], [link3].
How can I fix the CVE-2020-27842 vulnerability?
To fix the CVE-2020-27842 vulnerability, update openjpeg to version 2.4.0 or higher.