#VU21456 Infinite loop in OpenJPEG - CVE-2019-12973
Published: October 1, 2019 / Updated: December 29, 2020
OpenJPEG
openjpeg.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c in Open JPEG. A remote attacker can create a specially crafted .bmp file, pass it to the affected application and perform denial of service (DoS) attack.
Remediation
External links
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00088.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00090.html
- http://www.securityfocus.com/bid/108900
- https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67b11ec3
- https://github.com/uclouvain/openjpeg/pull/1185/commits/cbe7384016083eac16078b359acd7a842253d503
- https://github.com/uclouvain/openjpeg/blob/v2.4.0/CHANGELOG.md