CVE-2017-17479

SOURCE - nist

Summary

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

EPSS Score: 0.01306 (0.859)

Common Weakness Enumeration (CWE)

SOURCE - nist

Out-of-bounds Write

SOURCE - redhat

Stack-based Buffer Overflow


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/openjpeg2debdebian12>=2.5.0-2Not yet available
debian/openjpeg2debdebian10>=2.3.0-2+deb10u2Not yet available
debian/openjpeg2debdebianunstable>=2.5.0-2Not yet available
debian/openjpeg2debdebian13>=2.5.0-2Not yet available
debian/openjpeg2debdebian11>=2.4.0-3Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

9.8critical

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

9.8medium

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.8


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.3medium

suse

CREATED


UPDATED



EXPLOITABILITY SCORE

3.9


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

7.3medium