uclouvain openjpeg
cpe:2.3:a:openjpeg:openjpeg:*:*:*:*:*:*:*, +1 more
- <= 2.5.0
A NULL pointer dereference vulnerability has been identified in OpenJPEG version 2.5.0 and prior. The issue arises in the DWT component, specifically within the 'dwt.c' file.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash.
The vulnerability can be reproduced by compiling OpenJPEG with Clang, using the Undefined Behavior Sanitizer. After building and installing the application, the 'opj_decompress' command can be used to process a crafted file that triggers the NULL pointer dereference.
Users can upgrade to OpenJPEG version 2.5.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.