605
VMScore

CVE-2021-36089

Published: 01/07/2021 Updated: 06/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Grok 7.6.6 up to and including 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zope grok

Vendor Advisories

Debian Bug report logs - #990525 libgrokj2k: CVE-2021-36089 Package: src:libgrokj2k; Maintainer for src:libgrokj2k is Aaron Boxer <boxerab@gmailcom>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 1 Jul 2021 11:27:02 UTC Severity: grave Tags: security, upstream Found in version libgrokj2k/766-3 ...