Vulnerability Description
A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uclouvain | Openjpeg | <= 1.5.1 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1901998Issue TrackingPatchThird Party Advisory
- https://github.com/uclouvain/openjpeg/issues/1283ExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00011.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202101-29Third Party Advisory
- https://www.debian.org/security/2021/dsa-4882Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1901998Issue TrackingPatchThird Party Advisory
- https://github.com/uclouvain/openjpeg/issues/1283ExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00011.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202101-29Third Party Advisory
- https://www.debian.org/security/2021/dsa-4882Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
FAQ
What is CVE-2020-27814?
CVE-2020-27814 is a vulnerability with a CVSS score of 7.8 (HIGH). A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the p...
How severe is CVE-2020-27814?
CVE-2020-27814 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27814?
Check the references section above for vendor advisories and patch information. Affected products include: Uclouvain Openjpeg, Debian Debian Linux.