CVE-2020-27824 log

Source
Severity Medium
Remote No
Type Denial of service
Description
In OpenJPEG before version 2.4.0, if too many decomposition levels are supplied to the encoder, it could cause a global buffer overflow to out-of-bounds read in the opj_dwt_calc_explicit_stepsizes() function.
Group Package Affected Fixed Severity Status Ticket
AVG-1339 openjpeg2 2.3.1-2 2.4.0-1 Medium Fixed
Date Advisory Group Package Severity Type
09 Dec 2020 ASA-202012-21 AVG-1339 openjpeg2 Medium multiple issues
References
https://github.com/uclouvain/openjpeg/issues/1286
https://github.com/uclouvain/openjpeg/pull/1292
https://github.com/uclouvain/openjpeg/commit/6daf5f3e1ec6eff03b7982889874a3de6617db8d