A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://blogs.gentoo.org/ago/2017/08/28/openjpeg-stack-based-buffer-overflow-write-in-pgxtoimage-convert-c/ | vdb entry third party advisory patch |
https://github.com/uclouvain/openjpeg/commit/e5285319229a5d77bf316bb0d3a6cbd3cb8666d9 | issue tracking third party advisory patch |
http://www.securityfocus.com/bid/100555 | vdb entry third party advisory |
https://github.com/uclouvain/openjpeg/issues/997 | issue tracking third party advisory patch |
http://www.debian.org/security/2017/dsa-4013 | third party advisory vendor advisory |