Bug 1728513 (CVE-2018-20846) - CVE-2018-20846 openjpeg: out-of-bounds read in functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c leads to denial of service
Summary: CVE-2018-20846 openjpeg: out-of-bounds read in functions pi_next_lrcp, pi_nex...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-20846
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1728514 1728515 1734329 1734330 1734331
Blocks: 1728516
TreeView+ depends on / blocked
 
Reported: 2019-07-10 06:05 UTC by Dhananjay Arunesh
Modified: 2021-10-27 10:46 UTC (History)
14 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-27 10:46:17 UTC
Embargoed:


Attachments (Terms of Use)

Description Dhananjay Arunesh 2019-07-10 06:05:40 UTC
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

Reference:
https://github.com/uclouvain/openjpeg/pull/1168/commits/c277159986c80142180fbe5efb256bbf3bdf3edc

Comment 1 Dhananjay Arunesh 2019-07-10 06:05:59 UTC
Created openjpeg tracking bugs for this issue:

Affects: fedora-all [bug 1728515]


Created openjpeg2 tracking bugs for this issue:

Affects: epel-all [bug 1728514]

Comment 2 Sandro Mani 2019-07-10 12:16:01 UTC
The patch is already part of openjpeg-2.3.1, which is F28+ and epel7.

Comment 3 Riccardo Schirone 2019-07-17 09:37:14 UTC
According to https://github.com/uclouvain/openjpeg/pull/1168#commitcomment-32961642 the patch https://github.com/uclouvain/openjpeg/commit/e1740e7ce79d0a1676db4da0f4189b64e85f52cb was reverted because it did not compile.


Note You need to log in before you can comment on or make changes to this bug.