Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
The product divides a value by zero.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2018/12/msg00013.html | issue tracking mailing list third party advisory |
https://github.com/uclouvain/openjpeg/issues/1123 | exploit third party advisory patch |
https://www.debian.org/security/2019/dsa-4405 | third party advisory vendor advisory |
https://usn.ubuntu.com/4109-1/ | vendor advisory |