CVE-2020-15389
—CVSS 3.1
6.5 medium
EPSS
3%p84
Published
()
Modified
Description
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.
In the news0 stories
No ingested article mentions this CVE yet.