CVE-2020-27844 PUBLISHED

A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

EPSS 0.78% · 73.5th percentile

Risk Scores

EPSS Score
0.78%
73.5th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSinsighttoolkit40, 4.13.3withdata-dfsg1-4.1, 4.13.3withdata-dfsg2-1ubuntu1
Ubuntu:20.04:LTSinsighttoolkit44.13.2-dfsg1-4ubuntu1, 4.13.2-dfsg1-6, 4.13.2-dfsg1-6ubuntu1
Ubuntu:18.04:LTSinsighttoolkit40, 4.12.2-dfsg1-1ubuntu1
Ubuntu:16.04:LTSinsighttoolkit44.8.1-1ubuntu4, 4.8.2-3.1ubuntu1, 0

Timeline

References

Open in Interactive Console →