5.5
CVSSv3

CVE-2020-27842

Published: 05/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

There's a flaw in openjpeg's t2 encoder in versions before 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uclouvain openjpeg

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject extra packages for enterprise linux 7.0

debian debian linux 9.0

debian debian linux 10.0

redhat enterprise linux 8.0

redhat enterprise linux for power little endian 8.0

redhat enterprise linux for ibm z systems 8.0

redhat codeready linux builder for ibm z systems 8.0

redhat codeready linux builder 8.0

redhat codeready linux builder for power little endian 8.0

oracle outside in technology 8.5.5

Vendor Advisories

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, which could result in denial of service or the execution of arbitrary code when opening a malformed image For the stable distribution (buster), these problems have been fixed in version 230-2+deb10u2 We recommend that you upgrade your openjpeg2 packages ...
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pic in OpenJPEG through 230 allow remote attackers to cause a denial of service (application crash) (CVE-2018-20845) An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pic in Ope ...
A null pointer dereference issue was found in lib/openjp2/tgtc when a small precincts size, the option "-TP C" and non (0,0) grid offset are given in OpenJPEG 231 ...