Integer overflow in OpenJPEG - CVE-2018-5727

 

Integer overflow in OpenJPEG - CVE-2018-5727

Published: January 16, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37631
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5727
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.


Affected software

OpenJPEG
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
SUSE Linux Enterprise Module for Packagehub Subpackages
libopenjp2-7
libopenjp2-7-debuginfo
openjpeg2
openjpeg2-debuginfo
openjpeg2-debugsource
openjpeg2-devel
libopenjp2-7-32bit
libopenjp2-7-32bit-debuginfo
ghostscript (Ubuntu package)
libgs9 (Ubuntu package)

How to mitigate CVE-2018-5727

Install update from vendor's website.

libopenjp2-7 - update to 2.3.0-150000.3.5.1
libopenjp2-7-debuginfo - update to 2.3.0-150000.3.5.1
openjpeg2 - update to 2.3.0-150000.3.5.1
openjpeg2-debuginfo - update to 2.3.0-150000.3.5.1
openjpeg2-debugsource - update to 2.3.0-150000.3.5.1
openjpeg2-devel - update to 2.3.0-150000.3.5.1
libopenjp2-7-32bit - update to 2.3.0-150000.3.5.1
libopenjp2-7-32bit-debuginfo - update to 2.3.0-150000.3.5.1
ghostscript (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.14, 9.26~dfsg+0-0ubuntu0.18.04.14
libgs9 (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.14, 9.26~dfsg+0-0ubuntu0.18.04.14

External References

Related Security Bulletins