Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2019-6988, CVE-2018-20846 and CVE-2018-16376 #1328

Closed
stnert opened this issue Jan 28, 2021 · 1 comment
Closed

CVE-2019-6988, CVE-2018-20846 and CVE-2018-16376 #1328

stnert opened this issue Jan 28, 2021 · 1 comment

Comments

@stnert
Copy link

stnert commented Jan 28, 2021

  1. An issue has been discovered in OpenJPEG 2.4.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) -> Type: Denial of service

  2. Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG -> Type: Denial of service

  3. An issue was discovered in OpenJPEG 2.4.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. -> Type: Arbitrary code execution

Any forecast for correction?

@rouault
Copy link
Collaborator

rouault commented May 6, 2021

1. An issue has been discovered in OpenJPEG 2.4.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation)   -> Type: Denial of service

Duplicate of #1178

  • Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG -> Type: Denial of service

  • An issue was discovered in OpenJPEG 2.4.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. -> Type: Arbitrary code execution

No longer relevant since #1350

@rouault rouault closed this as completed May 6, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants