Related Vulnerabilities: CVE-2020-27824  

In openjpeg v2.3.1 and prior, if too many decomposition levels are supplied to the encoder, it could cause a global buffer overflow to out-of-bounds read in the opj_dwt_calc_explicit_stepsizes() function.

Severity Medium

Remote No

Type Denial of service

Description

In openjpeg v2.3.1 and prior, if too many decomposition levels are supplied to the encoder, it could cause a global buffer overflow to out-of-bounds read in the opj_dwt_calc_explicit_stepsizes() function.

AVG-1343 openjpeg2 2.3.1-3 Medium Vulnerable

https://github.com/uclouvain/openjpeg/issues/1286
https://github.com/uclouvain/openjpeg/pull/1292
https://github.com/uclouvain/openjpeg/commit/6daf5f3e1ec6eff03b7982889874a3de6617db8d