First published: Wed Jun 26 2019(Updated: )
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclouvain Openjpeg | <=2.3.0 |
https://github.com/uclouvain/openjpeg/pull/1168/commits/c277159986c80142180fbe5efb256bbf3bdf3edc
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20846 is a vulnerability that allows remote attackers to cause a denial of service in OpenJPEG through version 2.3.0.
The functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c are affected by CVE-2018-20846.
CVE-2018-20846 has a severity rating of medium with a score of 6.5.
There is currently no available fix for CVE-2018-20846. It is recommended to update to a version of OpenJPEG that is not affected by the vulnerability, once a fix is released.
You can find more information about CVE-2018-20846 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108921) and [GitHub](https://github.com/uclouvain/openjpeg/pull/1168/commits/c277159986c80142180fbe5efb256bbf3bdf3edc).