CVE-2018-20847

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
26/06/2019
Last modified:
27/02/2023

Description

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:* 2.3.0 (including)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*