First published: Tue Jan 28 2020(Updated: )
A heap-based buffer overflow in the qmfbid==1 case in opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28. Upstream Issue: <a href="https://github.com/uclouvain/openjpeg/issues/1231">https://github.com/uclouvain/openjpeg/issues/1231</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjpeg2 | 2.4.0-3 2.5.0-2 | |
uclouvain openjpeg | =2.3.1 | |
Debian | =8.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8112 is a vulnerability in OpenJPEG that allows for a heap-based buffer overflow.
CVE-2020-8112 has a severity rating of 8.8, which is considered high.
CVE-2020-8112 can lead to a heap-based buffer overflow in OpenJPEG 2.3.1 through 2020-01-28.
To fix CVE-2020-8112, users should update to OpenJPEG version 2.3.1 or later.
More information about CVE-2020-8112 can be found at the following references: [link1], [link2], [link3].