First published: Mon Sep 03 2018(Updated: )
An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjpeg2 | <=2.4.0-3<=2.5.0-2 | |
OpenJPEG | =2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-16375.
The severity level of CVE-2018-16375 is high.
The affected software is OpenJPEG version 2.3.0-2+.
The remedy for this vulnerability is to update OpenJPEG to version 2.3.1 or higher.
More information about CVE-2018-16375 can be found at the following references: [CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16375), [GitHub issue](https://github.com/uclouvain/openjpeg/issues/1126), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-16375).