CVE-2020-6851
גבוהה 7.5
תיאור (מקור, אנגלית)
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 5% (אחוזון 100) נכון ל-23/9/2026
- CWE
- CWE-787
מוצרים מושפעים
uclouvain: openjpeg; fedoraproject: fedora; debian: debian linux; redhat: enterprise linux; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux server; redhat: enterprise linux server aus; redhat: enterprise linux server tus; redhat: enterprise linux workstation; oracle: georaster; oracle: outside in technology
קישורים
- https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
- https://github.com/uclouvain/openjpeg/issues/1228 ExploitThird Party Advisory
- https://github.com/uclouvain/openjpeg/issues/1228 ExploitThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0262 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0274 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0296 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00025.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00008.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…