In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
Out-of-bounds Write
Stack-based Buffer Overflow
-
Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
debian/openjpeg2 | deb | debian | 12 | >=2.5.0-2 | Not yet available |
debian/openjpeg2 | deb | debian | 10 | >=2.3.0-2+deb10u2 | Not yet available |
debian/openjpeg2 | deb | debian | unstable | >=2.5.0-2 | Not yet available |
debian/openjpeg2 | deb | debian | 13 | >=2.5.0-2 | Not yet available |
debian/openjpeg2 | deb | debian | 11 | >=2.4.0-3 | Not yet available |
Severity and metrics
No CVSS data available from this source.
3.9
3.9
1.8
3.9