CVE-2020-8112: Buffer Overflow
A heap-based buffer overflow in the qmfbid==1 case in opjt1clbldecodeprocessor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28.
Upstream Issue:
https://github.com/uclouvain/openjpeg/issues/1231
Other sources
opjt1clbldecodeprocessor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openjpeg2to a version that resolves this vulnerability.Fixed in 2.4.0-3Fixed in 2.4.0-3+deb11u1Fixed in 2.5.0-2+deb12u1Fixed in 2.5.3-2
Event History
Frequently Asked Questions
What is CVE-2020-8112?
CVE-2020-8112 is a vulnerability in OpenJPEG that allows for a heap-based buffer overflow.
What is the severity of CVE-2020-8112?
CVE-2020-8112 has a severity rating of 8.8, which is considered high.
How does CVE-2020-8112 impact the affected software?
CVE-2020-8112 can lead to a heap-based buffer overflow in OpenJPEG 2.3.1 through 2020-01-28.
How can I fix CVE-2020-8112?
To fix CVE-2020-8112, users should update to OpenJPEG version 2.3.1 or later.
Where can I find more information about CVE-2020-8112?
More information about CVE-2020-8112 can be found at the following references: [link1], [link2], [link3].