Heap corruption via unchecked PLT buffer subtraction
Published Jan 5, 2021 · Updated Aug 4, 2024
Heap-based buffer overflow in OpenJPEG before 2.4.0 allows context-dependent attackers to corrupt memory through crafted encoding input. opj_j2k_write_sod subtracts reserved PLT bytes from the remaining output-buffer length after relying on a debug-only assertion, so opj_t2_encode_packet performs an out-of-bounds copy. Triggering requires conversion or encoding of untrusted input with crafted progression-order parameters; reading an image alone does not reach the flaw, and the process can crash or suffer memory corruption.
Summary
What happened
Heap-based buffer overflow in OpenJPEG before 2.4.0 allows context-dependent attackers to corrupt memory through crafted encoding input. opj_j2k_write_sod subtracts reserved PLT bytes from the remaining output-buffer length after relying on a debug-only assertion, so opj_t2_encode_packet performs an out-of-bounds copy. Triggering requires conversion or encoding of untrusted input with crafted progression-order parameters; reading an image alone does not reach the flaw, and the process can crash or suffer memory corruption.
The record
- CVE
- CVE-2020-27844
- Published
- Jan 5, 2021
- Updated
- Aug 4, 2024
- Vendor
- Université catholique de Louvain
- Product
- OpenJPEG
- Classifications
- CWE-20, T1203
- Attack vector
- local
- Privileges
- Unavailable
Timeline
How it unfolded
- Jan 5, 2021CVE publishedPublication date reported by the CVE source.
- Aug 4, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=openjpeg 2.4.0
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- OpenJPEG issue 1299 heap-overflow reproducerproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo