CVE-2023-39327: Openjpeg: malicious files can cause the program to enter a large loop
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
Other sources
In openjpeg, maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
References:
https://github.com/uclouvain/openjpeg/issues/1472
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39327?
CVE-2023-39327 is considered a moderate vulnerability due to its ability to cause denial-of-service through infinite loops.
How do I fix CVE-2023-39327?
To mitigate CVE-2023-39327, upgrade OpenJPEG to version 2.4.0-4 or higher, or to 2.5.0-3 or higher.
Which versions of OpenJPEG are affected by CVE-2023-39327?
CVE-2023-39327 affects OpenJPEG versions up to and including 2.4.0-3 and 2.5.0-2.
What kind of attack does CVE-2023-39327 allow?
CVE-2023-39327 allows for denial-of-service attacks by processing specially crafted images that lead to excessive warning messages.
Is CVE-2023-39327 being actively exploited?
As of now, there are no reports indicating that CVE-2023-39327 is being actively exploited in the wild.