First published: Wed Jun 26 2019(Updated: )
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclouvain Openjpeg | <=2.3.0 | |
redhat/openjpeg | <2.3.1 | 2.3.1 |
debian/openjpeg2 | 2.4.0-3 2.5.0-2 |
https://github.com/uclouvain/openjpeg/pull/1168/commits/c5bd64ea146162967c29bd2af0cbb845ba3eaaaf
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20845 is a division-by-zero vulnerability in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in OpenJPEG through version 2.3.0.
The severity of CVE-2018-20845 is medium with a CVSS score of 6.5.
Remote attackers can exploit CVE-2018-20845 to cause a denial of service (application crash).
The affected software includes OpenJPEG version up to and including 2.3.0.
To fix CVE-2018-20845, update OpenJPEG to version 2.3.1 or later.