CVE-2009-5030: Buffer Overflow
The tcdfreeencode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5030?
CVE-2009-5030 is classified as a high severity vulnerability due to its potential to cause denial of service and possibly execute arbitrary code.
How do I fix CVE-2009-5030?
To fix CVE-2009-5030, update OpenJPEG to a version beyond 1.5 that addresses this vulnerability.
What types of attacks can CVE-2009-5030 allow?
CVE-2009-5030 can allow remote attackers to execute arbitrary code or cause a denial of service by exploiting crafted Gray16 TIFF images.
Which versions of OpenJPEG are affected by CVE-2009-5030?
CVE-2009-5030 affects OpenJPEG versions 1.3, 1.4, and 1.5.
What is the impact of CVE-2009-5030 on users?
The impact of CVE-2009-5030 on users includes potential system crashes and unauthorized code execution leading to compromised system security.