cbcvebase.
CVE-2018-6616
published 2018-02-04

CVE-2018-6616: In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.

Affected

22 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianopenjpeg2< openjpeg2 2.4.0-1 (bookworm)openjpeg2 2.4.0-1 (bookworm)
debianopenjpeg2< openjpeg2 2.3.0-2 (bookworm)openjpeg2 2.3.0-2 (bookworm)
opensuseleap
opensuseleap
oracledatabase_server
oraclegeoraster
oracleoutside_in_technology
oracleoutside_in_technology
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-22.3.0-2
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-2build0.18.04.12.3.0-2build0.18.04.1
uclouvainopenjpeg
uclouvainopenjpeg

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv9.8CRITICAL