CVE-2017-12982
Summary
| CVE | CVE-2017-12982 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-21 07:29:00 UTC |
| Updated | 2021-02-02 19:56:00 UTC |
| Description | The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| memory allocation failure in opj_aligned_alloc_n (opj_malloc.c) · Issue #983 · uclouvain/openjpeg · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| OpenJPEG: Multiple vulnerabilities (GLSA 201710-26) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| bmp_read_info_header(): reject bmp files with biBitCount == 0 (#983) · uclouvain/openjpeg@baf0c1a · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| openjpeg: memory allocation failure in opj_aligned_alloc_n (opj_malloc.c) | agostino's blog | MISC | blogs.gentoo.org | Patch, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.