First published: Mon Jan 28 2019(Updated: )
An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uclouvain Openjpeg | =2.3.0 | |
=2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6988 is a vulnerability discovered in OpenJPEG 2.3.0 that allows remote attackers to cause a denial of service by performing excessive memory allocation.
The severity of CVE-2019-6988 is medium, with a severity value of 6.5.
CVE-2019-6988 affects OpenJPEG 2.3.0, potentially allowing remote attackers to cause a denial of service.
To fix CVE-2019-6988, it is recommended to update OpenJPEG to a version that is not affected by the vulnerability.
You can find more information about CVE-2019-6988 in the references provided: http://www.securityfocus.com/bid/106785 and https://github.com/uclouvain/openjpeg/issues/1178.