cbcvebase.
CVE-2018-7648
published 2018-03-02

CVE-2018-7648: An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianopenjpeg2< openjpeg2 2.3.1-1 (bookworm)openjpeg2 2.3.1-1 (bookworm)
the_openjpeg_projectopenjpeg2>= 0 < 2.3.1-12.3.1-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.1-12.3.1-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.1-12.3.1-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.1-12.3.1-1
uclouvainopenjpeg

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL