CVE-2020-6851: Buffer Overflow
Last updated 24 July 2024
Other sources
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opjt1clbldecodeprocessor in libopenjp2.so.
Upstream Issue:
https://github.com/uclouvain/openjpeg/issues/1228
— Red Hat
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opjt1clbldecodeprocessor in openjp2/t1.c because of lack of opjj2kupdateimagedimensions validation.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openjpeg2to a version that resolves this vulnerability.Fixed in 2.4.0-3Fixed in 2.4.0-3+deb11u1Fixed in 2.5.0-2+deb12u1Fixed in 2.5.3-2 - Upgrade
Upgrade
openjpegto a version that resolves this vulnerability.Fixed in 2.3.1 - Compensating control
Mitigate the risk of the heap-based buffer overflow in opj_t1_clbl_decode_processor by restricting or isolating any service/process that uses libopenjp2.so (openjpeg) to trusted inputs/users, since the issue is triggered in openjp2/t1.c (lack of opj_j2k_update_image_dimensions validation).
Event History
Frequently Asked Questions
What is CVE-2020-6851?
CVE-2020-6851 is a vulnerability in OpenJPEG that allows for a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c.
What is the severity of CVE-2020-6851?
The severity of CVE-2020-6851 is high, with a severity value of 7.5.
How does CVE-2020-6851 affect OpenJPEG?
CVE-2020-6851 affects OpenJPEG versions up to 2.3.1.
What is the recommended remedy for CVE-2020-6851?
The recommended remedy for CVE-2020-6851 is to update OpenJPEG to version 2.3.1-1ubuntu4 or higher.
Where can I find more information about CVE-2020-6851?
You can find more information about CVE-2020-6851 on the CVE website and the Ubuntu security notices.