An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_mqc_flush in lib/openjp2/mqc.c and opj_t1_encode_cblk in lib/openjp2/t1.c) or possibly remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:20:40.828Z
Reserved: 2017-09-05T00:00:00
Link: CVE-2017-14151

No data.

Status : Modified
Published: 2017-09-05T16:29:00.213
Modified: 2024-11-21T03:12:14.573
Link: CVE-2017-14151
