Severity
5.5MEDIUM
EPSS
0.3%
top 49.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMar 15

Description

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDuclouvain/openjpeg< 2.4.0
Debianopenjpeg2< 2.4.0-1+3
CVEListV5openjpegopenjpeg 2.4.0

Also affects: Debian Linux 10.0, 9.0, Fedora 32, 33, Enterprise Linux 8.0

Patches

🔴Vulnerability Details

4
OSV
openjpeg2 vulnerabilities2023-03-15
GHSA
GHSA-4w56-x77j-f3vc: A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function2022-05-24
OSV
CVE-2020-27824: A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function2021-05-13
CVEList
CVE-2020-27824: A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function2021-05-13

📋Vendor Advisories

8
Ubuntu
OpenJPEG vulnerabilities2023-03-15
Ubuntu
OpenJPEG vulnerabilities2022-10-07
Microsoft
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. 2021-05-11
Ubuntu
OpenJPEG vulnerabilities2021-03-16
Ubuntu
Ghostscript vulnerabilities2021-01-07
CVE-2020-27824 (MEDIUM CVSS 5.5) | A flaw was found in OpenJPEG’s enco | cvebase.io