4.3

CVE-2023-39327

Openjpeg: malicious files can cause the program to enter a large loop

A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Uclouvain ≫ Openjpeg Version -
   Redhat ≫ Enterprise Linux Version 6.0
   Redhat ≫ Enterprise Linux Version 7.0
Uclouvain ≫ Openjpeg Version 2.0
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
   Redhat ≫ Enterprise Linux Version 9.0
Uclouvain ≫ Openjpeg Version 2.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.404
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://bugzilla.redhat.com/show_bug.cgi?id=2295812
Third Party Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:4128
https://access.redhat.com/security/cve/CVE-2023-39327
Third Party Advisory
https://github.com/uclouvain/openjpeg/issues/1472