UBUNTU-CVE-2017-12982
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-12982
UBUNTU-CVE-2017-12982
Summary:
Details: The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.
References: https://ubuntu.com/security/CVE-2017-12982, https://blogs.gentoo.org/ago/2017/08/14/openjpeg-memory-allocation-failure-in-opj_aligned_alloc_n-opj_malloc-c/, https://ubuntu.com/security/notices/USN-4782-1, https://www.cve.org/CVERecord?id=CVE-2017-12982
Affected packages
Package
Name: openjpeg2
Purl: pkg:deb/ubuntu/[email protected]+deb9u6ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
