First published: Thu Jul 04 2024(Updated: )
In openjepg, a resource exhaustion can occur in the opj_t1_decode_cblks function in the tcd.c through a crafted image file causing a denial of service. References: <a href="https://github.com/uclouvain/openjpeg/issues/1474">https://github.com/uclouvain/openjpeg/issues/1474</a>
Affected Software | Affected Version | How to fix |
---|---|---|
uclouvain openjpeg |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2295816 is classified as a denial of service vulnerability due to resource exhaustion in the OpenJPEG library.
To mitigate REDHAT-BUG-2295816, update to the latest version of the OpenJPEG library provided by UCLouvain.
The vulnerability REDHAT-BUG-2295816 is triggered by processing a crafted image file that causes resource exhaustion.
The vulnerable software associated with REDHAT-BUG-2295816 is the UCLouvain OpenJPEG library.
Yes, REDHAT-BUG-2295816 can potentially be exploited remotely if an attacker can deliver a crafted image file to the vulnerable system.