CVE-2020-27814

high

Description

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

References

https://www.oracle.com//security-alerts/cpujul2021.html

https://www.debian.org/security/2021/dsa-4882

https://security.gentoo.org/glsa/202101-29

https://lists.debian.org/debian-lts-announce/2021/02/msg00011.html

https://github.com/uclouvain/openjpeg/issues/1283

https://bugzilla.redhat.com/show_bug.cgi?id=1901998

Details

Source: Mitre, NVD

Published: 2021-01-26

Updated: 2022-10-07

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High