Vulnerability Description
An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uclouvain | Openjpeg | <= 2.3.0 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/108921Broken LinkThird Party AdvisoryVDB Entry
- https://github.com/uclouvain/openjpeg/commit/5d00b719f4b93b1445e6fb4c766b9a9883cPatch
- https://github.com/uclouvain/openjpeg/issues/431Issue TrackingPatchThird Party Advisory
- https://github.com/uclouvain/openjpeg/pull/1168/commits/c58df149900df862806d0e89Patch
- https://lists.debian.org/debian-lts-announce/2019/07/msg00010.htmlIssue TrackingThird Party Advisory
- http://www.securityfocus.com/bid/108921Broken LinkThird Party AdvisoryVDB Entry
- https://github.com/uclouvain/openjpeg/commit/5d00b719f4b93b1445e6fb4c766b9a9883cPatch
- https://github.com/uclouvain/openjpeg/issues/431Issue TrackingPatchThird Party Advisory
- https://github.com/uclouvain/openjpeg/pull/1168/commits/c58df149900df862806d0e89Patch
- https://lists.debian.org/debian-lts-announce/2019/07/msg00010.htmlIssue TrackingThird Party Advisory
FAQ
What is CVE-2018-20847?
CVE-2018-20847 is a vulnerability with a CVSS score of 8.8 (HIGH). An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.
How severe is CVE-2018-20847?
CVE-2018-20847 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20847?
Check the references section above for vendor advisories and patch information. Affected products include: Uclouvain Openjpeg, Debian Debian Linux.