|
|
| |
|
| |
openjpeg: code execution
| Package(s): | openjpeg |
CVE #(s): | CVE-2009-5030
|
| Created: | June 28, 2012 |
Updated: | July 11, 2012 |
| Description: |
From the Red Hat bug report:
An out-of heap-based buffer bounds read and write flaw, leading to invalid free, was found in the way a tile coder / decoder (TCD) implementation of OpenJPEG, an open-source JPEG 2000 codec written in C language, performed releasing of previously allocated memory for the TCD encoder handle by processing certain Gray16 TIFF images. A remote attacker could provide a specially-crafted TIFF image file, which once converted into the JPEG 2000 file format with an application linked against OpenJPEG (such as 'image_to_j2k'), would lead to that application crash, or, potentially arbitrary code execution with the privileges of the user running the application. |
| Alerts: |
|
( Log in to post comments)
|
|
|