An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_mqc_flush in lib/openjp2/mqc.c and opj_t1_encode_cblk in lib/openjp2/t1.c) or possibly remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-09-05T16:00:00
Updated: 2024-08-05T19:20:40.828Z
Reserved: 2017-09-05T00:00:00
Link: CVE-2017-14151
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-09-05T16:29:00.213
Modified: 2024-11-21T03:12:14.573
Link: CVE-2017-14151
Redhat