CVE-2020-6851: Buffer Overflow
Last updated 24 July 2024
Other sources
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opjt1clbldecodeprocessor in libopenjp2.so.
Upstream Issue:
https://github.com/uclouvain/openjpeg/issues/1228
— Red Hat
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opjt1clbldecodeprocessor in openjp2/t1.c because of lack of opjj2kupdateimagedimensions validation.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-6851?
CVE-2020-6851 is a vulnerability in OpenJPEG that allows for a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c.
What is the severity of CVE-2020-6851?
The severity of CVE-2020-6851 is high, with a severity value of 7.5.
How does CVE-2020-6851 affect OpenJPEG?
CVE-2020-6851 affects OpenJPEG versions up to 2.3.1.
What is the recommended remedy for CVE-2020-6851?
The recommended remedy for CVE-2020-6851 is to update OpenJPEG to version 2.3.1-1ubuntu4 or higher.
Where can I find more information about CVE-2020-6851?
You can find more information about CVE-2020-6851 on the CVE website and the Ubuntu security notices.