CVE-2020-27823 - log back

CVE-2020-27823 edited at 09 Dec 2020 11:02:22
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ In openjpeg2 version 2.3.1 and prior, there is a heap buffer overflow in opj_tcd_dc_level_shift_encode() causing an out-of-bounds WRITE when crafted input is processed by the encoder and the -d option is used.
References
+ https://github.com/uclouvain/openjpeg/issues/1284
+ https://github.com/uclouvain/openjpeg/commit/b2072402b7e14d22bba6fb8cde2a1e9996e9a919
Notes
CVE-2020-27823 created at 09 Dec 2020 11:00:09