ZeroHour

CVE-2020-27842

CVSS 3.1
5.5 medium
EPSS
2%p73
Published
()
Modified
Description

There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.

Vendors
uclouvainfedoraprojectdebianredhatoracle
Products
openjpeg, extra packages for enterprise linux, fedora, debian linux, codeready linux builder, codeready linux builder for ibm z systems, codeready linux builder for power little endian, enterprise linux, enterprise linux for ibm z systems, enterprise linux for power little endian, outside in technology
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.