CVE-2020-27843

NameCVE-2020-27843
DescriptionA flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2975-1, DSA-4882-1, ELA-596-1
Debian Bugs983663

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openjpeg2 (PTS)jessie, jessie (lts)2.1.0-2+deb8u14fixed
stretch (security), stretch (lts), stretch2.1.2-1.1+deb9u7fixed
buster (security), buster, buster (lts)2.3.0-2+deb10u2fixed
bullseye2.4.0-3fixed
sid, trixie, bookworm2.5.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openjpeg2sourcejessie2.1.0-2+deb8u13ELA-596-1
openjpeg2sourcestretch2.1.2-1.1+deb9u7DLA-2975-1
openjpeg2sourcebuster2.3.0-2+deb10u2DSA-4882-1
openjpeg2source(unstable)2.4.0-1983663

Notes

https://github.com/uclouvain/openjpeg/issues/1297
Partial fix (preventing the out of bounds access): https://github.com/uclouvain/openjpeg/commit/38d661a3897052c7ff0b39b30c29cb067e130121 (2.4.0)

Search for package or bug name: Reporting problems