CVE-2020-27814
CVE-2020-27814
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.0%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
25 Jan 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.
Affected products
n/a · openjpegWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://bugzilla.redhat.com/show_bug.cgi?id=1901998https://github.com/uclouvain/openjpeg/issues/1283https://lists.debian.org/debian-lts-announce/2021/02/msg00011.htmlhttps://security.gentoo.org/glsa/202101-29https://www.debian.org/security/2021/dsa-4882https://www.oracle.com//security-alerts/cpujul2021.html