Out-of-bounds write in Kakadu SDK - CVE-2017-2811

 

Out-of-bounds write in Kakadu SDK - CVE-2017-2811

Published: April 24, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37161
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2811
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.


Affected software

Kakadu SDK

How to mitigate CVE-2017-2811

Install update from vendor's website.


External References

Related Security Bulletins