First published: Thu Jul 15 2021(Updated: )
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ok-file-formats Project Ok-file-formats | <=2020-06-26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23706 is a heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() of ok-file-formats through 2020-06-26.
The vulnerability allows attackers to cause a Denial of Service (DOS) attack by using a crafted jpeg file.
CVE-2020-23706 affects Ok-file-formats through version 2020-06-26.
CVE-2020-23706 has a severity rating of medium (6.5).
At the time of writing, there is no known fix available for CVE-2020-23706. It is recommended to update to the latest version of Ok-file-formats when a fix is released.