CVE-2023-39328: Openjpeg: denail of service via crafted image file
A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.
Other sources
A vulnerability was found in OpenJPEG where an attacker remotely sends malicious pictures to allow the program to run, which can cause denial of service and exhaust system resources.
References:
https://github.com/uclouvain/openjpeg/issues/1471 https://github.com/uclouvain/openjpeg/pull/1470
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39328?
CVE-2023-39328 has been classified with a high severity due to its ability to cause application crashes.
How do I fix CVE-2023-39328?
To address CVE-2023-39328, update OpenJPEG to the latest version that includes patches for this vulnerability.
What type of attacks are possible with CVE-2023-39328?
CVE-2023-39328 allows attackers to exploit the vulnerability by sending maliciously crafted image files that can crash the application.
Which software is affected by CVE-2023-39328?
CVE-2023-39328 affects the OpenJPEG software developed by uclouvain.
Is there a workaround for CVE-2023-39328 if I cannot update?
Currently, there is no known workaround for CVE-2023-39328, so updating is the recommended approach.