|
|
| |
|
| |
openjpeg: code execution
| Package(s): | openjpeg |
CVE #(s): | CVE-2012-3358
|
| Created: | July 11, 2012 |
Updated: | July 16, 2012 |
| Description: |
From the Red Hat advisory:
An input validation flaw, leading to a heap-based buffer overflow, was
found in the way OpenJPEG handled the tile number and size in an image tile
header. A remote attacker could provide a specially-crafted image file
that, when decoded using an application linked against OpenJPEG, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. |
| Alerts: |
|
( Log in to post comments)
|
|
|