Out-of-bounds write in Kakadu SDK - CVE-2017-2812

 

Out-of-bounds write in Kakadu SDK - CVE-2017-2812

Published: April 24, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37162
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2812
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an out of bounds write causing an exploitable condition to arise.


Affected software

Kakadu SDK

How to mitigate CVE-2017-2812

Install update from vendor's website.


External References

Related Security Bulletins