Out-of-bounds write in Kakadu SDK - CVE-2017-2811
Published: April 24, 2018 / Updated: August 8, 2020
Kakadu SDK
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.