Bug 1905723 (CVE-2020-27824) - CVE-2020-27824 openjpeg: global-buffer-overflow read in opj_dwt_calc_explicit_stepsizes()
Summary: CVE-2020-27824 openjpeg: global-buffer-overflow read in opj_dwt_calc_explicit...
Alias: CVE-2020-27824
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1905724 1905725 1905726 1906216
Blocks: 1902194 1939849
TreeView+ depends on / blocked
Reported: 2020-12-08 22:28 UTC by Todd Cullum
Modified: 2021-11-09 17:56 UTC (History)
5 users (show)

Fixed In Version: openjpeg 2.4.0
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.
Clone Of:
Last Closed: 2021-11-02 18:00:28 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2021:4251 0 None None None 2021-11-09 17:56:22 UTC

Description Todd Cullum 2020-12-08 22:28:42 UTC
In openjpeg v2.3.1 and prior, if too many decomposition levels are supplied to the encoder, it could cause a global buffer overflow to out-of-bounds read in the opj_dwt_calc_explicit_stepsizes() function.

Reference: https://github.com/uclouvain/openjpeg/issues/1286
Upstream patch: https://github.com/uclouvain/openjpeg/pull/1292/commits/6daf5f3e1ec6eff03b7982889874a3de6617db8d

Comment 1 Todd Cullum 2020-12-08 22:30:57 UTC
Created openjpeg tracking bugs for this issue:

Affects: fedora-all [bug 1905724]

Created openjpeg2 tracking bugs for this issue:

Affects: epel-all [bug 1905726]
Affects: fedora-all [bug 1905725]

Comment 2 Todd Cullum 2020-12-09 00:52:45 UTC

Name: zodf0055980 (SQLab NCTU Taiwan)

Comment 5 errata-xmlrpc 2021-11-09 17:56:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:4251 https://access.redhat.com/errata/RHSA-2021:4251

Note You need to log in before you can comment on or make changes to this bug.