CVE-2020-8112 PUBLISHED

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

EPSS 1.79% · 82.6th percentile

Risk Scores

EPSS Score
1.79%
82.6th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10blender0, 4.3.2+dfsg-2ubuntu1, 4.3.2+dfsg-2ubuntu2
Ubuntu:20.04:LTSqtwebengine-opensource-src5.12.5+dfsg-7build1, 5.12.8+dfsg-0ubuntu1, 5.12.8+dfsg-0ubuntu1.1
Ubuntu:25.10qtwebengine-opensource-src5.15.19+dfsg2-1, 5.15.19+dfsg-1, 5.15.18+dfsg-2build1
Ubuntu:18.04:LTSqtwebengine-opensource-src5.9.1+dfsg-4ubuntu1, 5.9.1+dfsg-4, 0
Ubuntu:24.04:LTSblender4.0.2+dfsg-1ubuntu2, 4.0.2+dfsg-1ubuntu4, 4.0.2+dfsg-1ubuntu6
Ubuntu:16.04:LTSblender2.76.b+dfsg0-3build1, 0, 2.74+dfsg0-4build2
Ubuntu:18.04:LTStexmaker5.0.2-1build2, 5.0.2-1, 5.0.2-1build1
Ubuntu:18.04:LTSghostscript9.25~dfsg+1-0ubuntu0.18.04.2, 0, 9.21~dfsg+1-0ubuntu3
Ubuntu:20.04:LTSopenjpeg22.3.1-1ubuntu3, 0, 2.3.0-2
Ubuntu:25.10texmaker5.1.3+dfsg-3build1, 0, 5.1.3+dfsg-3
Ubuntu:18.04:LTSinsighttoolkit44.12.2-dfsg1-1ubuntu1, 0
Ubuntu:20.04:LTSinsighttoolkit44.13.2-dfsg1-6, 4.13.2-dfsg1-8, 4.13.2-dfsg1-6ubuntu1
Ubuntu:16.04:LTSghostscript9.18~dfsg~0-0ubuntu2.9, 9.18~dfsg~0-0ubuntu2.8, 9.18~dfsg~0-0ubuntu2.7
Ubuntu:20.04:LTStexmaker5.0.3-1build3, 0, 5.0.3-1build5
Ubuntu:22.04:LTSinsighttoolkit44.13.3withdata-dfsg1-4.1, 0, 4.13.3withdata-dfsg2-1ubuntu1
Ubuntu:16.04:LTStexmaker0, 4.4.1-1, 4.4.1-1.1
Ubuntu:16.04:LTSinsighttoolkit44.8.1-1ubuntu3, 0, 4.8.1-1ubuntu4
Ubuntu:20.04:LTSblender2.82.a+dfsg-1, 2.82+dfsg-1build1, 2.82+dfsg-1
Ubuntu:16.04:LTSopenjpeg22.1.2-1.1+deb9u2build0.1, 0, 2.1.0-2.1
Ubuntu:22.04:LTSblender2.93.3+dfsg-3, 0, 3.0.1+dfsg-7

…and 6 more

Timeline

References

Open in Interactive Console →