Related Vulnerabilities: CVE-2020-27823  

In openjpeg2 version 2.3.1 and prior, there is a heap buffer overflow in opj_tcd_dc_level_shift_encode() causing an out-of-bounds WRITE when crafted input is processed by the encoder and the -d option is used.

Severity Medium

Remote No

Type Arbitrary code execution

Description

In openjpeg2 version 2.3.1 and prior, there is a heap buffer overflow in opj_tcd_dc_level_shift_encode() causing an out-of-bounds WRITE when crafted input is processed by the encoder and the -d option is used.

AVG-1339 openjpeg2 2.3.1-2 Medium Vulnerable FS#68906

https://github.com/uclouvain/openjpeg/issues/1284
https://github.com/uclouvain/openjpeg/commit/b2072402b7e14d22bba6fb8cde2a1e9996e9a919