CVE-2019-12973
Summary
| CVE | CVE-2019-12973 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-26 18:15:00 UTC |
| Updated | 2022-10-05 20:37:00 UTC |
| Description | In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| convertbmp: detect invalid file dimensions early · uclouvain/openjpeg@8ee3352 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2020 |
MISC |
www.oracle.com |
Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| [security-announce] openSUSE-SU-2019:2222-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2223-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| Commit range not found · Pull Request #1185 · uclouvain/openjpeg · GitHub |
MISC |
github.com |
Broken Link |
| OpenJPEG CVE-2019-12973 Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| OpenJPEG: Multiple vulnerabilities (GLSA 202101-29) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| [SECURITY] [DLA 2277-1] openjpeg2 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159478 Oracle Enterprise Linux Security Update for openjpeg2 (ELSA-2021-4251)
- 239842 Red Hat Update for openjpeg2 (RHSA-2021:4251)
- 353122 Amazon Linux Security Advisory for openjpeg2 : ALAS2-2022-1741
- 500472 Alpine Linux Security Update for openjpeg
- 504229 Alpine Linux Security Update for openjpeg
- 671572 EulerOS Security Update for openjpeg2 (EulerOS-SA-2022-1577)
- 671747 EulerOS Security Update for openjpeg2 (EulerOS-SA-2022-1811)
- 671759 EulerOS Security Update for openjpeg2 (EulerOS-SA-2022-1794)
- 671802 EulerOS Security Update for openjpeg2 (EulerOS-SA-2022-1872)
- 671810 EulerOS Security Update for openjpeg2 (EulerOS-SA-2022-1848)
- 940171 AlmaLinux Security Update for openjpeg2 (ALSA-2021:4251)
- 960346 Rocky Linux Security Update for openjpeg2 (RLSA-2021:4251)