CVE-2017-14151: Buffer Overflow
An off-by-one error was discovered in opjtcdcodeblockencallocatedata in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opjmqcflush in lib/openjp2/mqc.c and opjt1encodecblk in lib/openjp2/t1.c) or possibly remote code execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14151?
CVE-2017-14151 has a high severity rating due to its potential for causing remote denial of service through heap-based buffer overflow.
How do I fix CVE-2017-14151?
To mitigate CVE-2017-14151, update OpenJPEG to the latest version where the vulnerability is patched.
What types of systems are affected by CVE-2017-14151?
CVE-2017-14151 affects OpenJPEG version 2.2.0 and Debian distributions 8.0 and 9.0.
What is the main impact of CVE-2017-14151?
The main impact of CVE-2017-14151 is the risk of remote denial of service due to an out-of-bounds write.
Is CVE-2017-14151 a known vulnerability in OpenJPEG?
Yes, CVE-2017-14151 is a known vulnerability that was identified in OpenJPEG version 2.2.0.