cbcvebase.
CVE-2017-17479
published 2017-12-08

CVE-2017-17479: In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianopenjpeg2< openjpeg2 2.3.0-2 (bookworm)openjpeg2 2.3.0-2 (bookworm)
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
uclouvainopenjpeg
uclouvainopenjpeg>= 0 < 1:1.5.2-3.1ubuntu0.1~esm21:1.5.2-3.1ubuntu0.1~esm2

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL