CVE-2017-2812
—CVSS 3.0
7.8 high
EPSS
1%p72
Published
()
Modified
Description
A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an out of bounds write causing an exploitable condition to arise.
- Vendors
- kakadusoftware
- Products
- kakadu sdk
- Weakness
- CWE-787
- Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.