CVE-2018-20846: Input Validation
Out-of-bounds accesses in the functions pinextlrcp, pinextrlcp, pinextrpcl, pinextpcrl, pinextrpcl, and pinextcprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-20846?
CVE-2018-20846 is a vulnerability that allows remote attackers to cause a denial of service in OpenJPEG through version 2.3.0.
What functions are affected by CVE-2018-20846?
The functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c are affected by CVE-2018-20846.
How severe is CVE-2018-20846?
CVE-2018-20846 has a severity rating of medium with a score of 6.5.
How can I fix CVE-2018-20846?
There is currently no available fix for CVE-2018-20846. It is recommended to update to a version of OpenJPEG that is not affected by the vulnerability, once a fix is released.
Where can I find more information about CVE-2018-20846?
You can find more information about CVE-2018-20846 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108921) and [GitHub](https://github.com/uclouvain/openjpeg/pull/1168/commits/c277159986c80142180fbe5efb256bbf3bdf3edc).