CVE-2023-39329: Openjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opjt1decodecblks function in tcd.c through a crafted image file, causing a denial of service.
Other sources
In openjepg, a resource exhaustion can occur in the opjt1decodecblks function in the tcd.c through a crafted image file causing a denial of service.
References:
https://github.com/uclouvain/openjpeg/issues/1474
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39329?
CVE-2023-39329 has been classified as a denial of service vulnerability due to resource exhaustion.
How do I fix CVE-2023-39329?
To fix CVE-2023-39329, update to the latest version of OpenJPEG that addresses this vulnerability.
What impact does CVE-2023-39329 have on OpenJPEG users?
CVE-2023-39329 can lead to application instability and potential denial of service when processing crafted image files.
Which software versions are affected by CVE-2023-39329?
CVE-2023-39329 affects all versions of OpenJPEG prior to the fix that addresses this vulnerability.
How can CVE-2023-39329 be exploited?
CVE-2023-39329 can be exploited by sending specially crafted image files to an application using OpenJPEG.