Skip to content

heap-based buffer overflow issue #102

Open
@prasadayush

Description

@prasadayush

A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.

Below are the risk factors associated to this issue -
Attack complexity: low, DoS - High, High severity, Remote execution

Vulnerability link - https://security-tracker.debian.org/tracker/CVE-2021-3575

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions