CVE-2020-27814

high

Description

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1901998

https://security.gentoo.org/glsa/202101-29

https://github.com/uclouvain/openjpeg/issues/1283

https://lists.debian.org/debian-lts-announce/2021/02/msg00011.html

https://www.debian.org/security/2021/dsa-4882

Details

Source: MITRE

Published: 2021-01-26

Updated: 2021-07-20

Type: CWE-122

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH