Vulnerability Description
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uclouvain | Openjpeg | 2.3.1 |
| Opensuse | Leap | 15.0 |
| Debian | Debian Linux | 9.0 |
| Oracle | Database Server | 18c |
| Oracle | Outside In Technology | 8.5.4 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108900Third Party AdvisoryVDB Entry
- https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67bPatchThird Party Advisory
- https://github.com/uclouvain/openjpeg/pull/1185/commits/cbe7384016083eac16078b35Broken Link
- https://lists.debian.org/debian-lts-announce/2020/07/msg00008.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202101-29Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108900Third Party AdvisoryVDB Entry
- https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67bPatchThird Party Advisory
- https://github.com/uclouvain/openjpeg/pull/1185/commits/cbe7384016083eac16078b35Broken Link
- https://lists.debian.org/debian-lts-announce/2020/07/msg00008.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2019-12973?
CVE-2019-12973 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp f...
How severe is CVE-2019-12973?
CVE-2019-12973 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12973?
Check the references section above for vendor advisories and patch information. Affected products include: Uclouvain Openjpeg, Opensuse Leap, Debian Debian Linux, Oracle Database Server, Oracle Outside In Technology.