CVE-2018-20846

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
26/06/2019
Last modified:
27/02/2023

Description

Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:* 2.3.0 (including)