CVE-2019-12973Excessive Iteration in Openjpeg

Severity
5.5MEDIUMNVD
OSV6.5
EPSS
0.1%
top 83.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 24

Description

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

Debianthe_openjpeg_project/openjpeg2< 2.4.0-1+3
Ubuntuthe_openjpeg_project/openjpeg2< 2.1.2-1.1+deb9u6ubuntu0.1~esm1+1
NVDopensuse/leap15.0, 15.1+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-xvfr-r8m7-6v65: In OpenJPEG 22022-05-24
OSV
openjpeg2 vulnerabilities2021-03-17
OSV
OpenJPEG vulnerabilities2020-09-15
OSV
CVE-2019-12973: In OpenJPEG 22019-06-26
CVEList
CVE-2019-12973: In OpenJPEG 22019-06-26

📋Vendor Advisories

4
Ubuntu
OpenJPEG vulnerabilities2021-03-17
Ubuntu
OpenJPEG vulnerabilities2020-09-15
Red Hat
openjpeg: denial of service in function opj_t1_encode_cblks in openjp2/t1.c2019-06-26
Debian
CVE-2019-12973: openjpeg2 - In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks funct...2019

💬Community

5
Bugzilla
CVE-2019-12973 openjpeg: denial of service in function opj_t1_encode_cblks in openjp2/t1.c2019-07-23
Bugzilla
CVE-2019-12973 openjpeg: denial of service in function opj_t1_encode_cblks in openjp2/t1.c [fedora-all]2019-07-23
Bugzilla
CVE-2019-12973 openjpeg2: openjpeg: denial of service in function opj_t1_encode_cblks in openjp2/t1.c [epel-all]2019-07-23
Bugzilla
CVE-2019-12973 openjpeg2: openjpeg: denial of service in function opj_t1_encode_cblks in openjp2/t1.c [fedora-all]2019-07-23
Bugzilla
CVE-2019-12973 mingw-openjpeg2: openjpeg: denial of service in function opj_t1_encode_cblks in openjp2/t1.c [fedora-all]2019-07-23
CVE-2019-12973 — Excessive Iteration in Openjpeg | cvebase