CVE-2017-12982

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
21/08/2017
Last modified:
20/04/2025

Description

The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:* 2.3.0 (excluding)