Vulnerability Description
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ok-File-Formats Project | Ok-File-Formats | <= 2020-06-26 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/122.htmlTechnical Description
- https://github.com/brackeen/ok-file-formats/issues/8ExploitIssue TrackingThird Party Advisory
- https://cwe.mitre.org/data/definitions/122.htmlTechnical Description
- https://github.com/brackeen/ok-file-formats/issues/8ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2020-23707?
CVE-2020-23707 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) ...
How severe is CVE-2020-23707?
CVE-2020-23707 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23707?
Check the references section above for vendor advisories and patch information. Affected products include: Ok-File-Formats Project Ok-File-Formats.