Vulnerability Description
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ok-File-Formats Project | Ok-File-Formats | <= 2020-06-26 |
Related Weaknesses (CWE)
References
- https://github.com/brackeen/ok-file-formats/issues/7ExploitIssue TrackingThird Party Advisory
- https://github.com/brackeen/ok-file-formats/issues/7ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-23706?
CVE-2020-23706 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS)...
How severe is CVE-2020-23706?
CVE-2020-23706 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23706?
Check the references section above for vendor advisories and patch information. Affected products include: Ok-File-Formats Project Ok-File-Formats.