cbcvebase.
CVE-2020-27842
published 2021-01-05

CVE-2020-27842: There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.

Affected

24 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianopenjpeg2< openjpeg2 2.4.0-1 (bookworm)openjpeg2 2.4.0-1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_openjpeg2_2.3.1-12_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
oracleoutside_in_technology
redhatcodeready_linux_builder
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_power_little_endian
redhatenterprise_linux
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_power_little_endian
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.4.0-12.4.0-1
the_openjpeg_projectopenjpeg2>= 0 < 2.3.0-2+deb10u2build0.18.04.12.3.0-2+deb10u2build0.18.04.1
the_openjpeg_projectopenjpeg2>= 0 < 2.1.2-1.1+deb9u6ubuntu0.1~esm32.1.2-1.1+deb9u6ubuntu0.1~esm3
uclouvainopenjpeg< 2.4.02.4.0
uclouvainopenjpeg

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM