Back to Database
Status published
High
CVE-2020-6851
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor...
Vulnerability Description
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-6851
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.debian.org/debian-lts-announce/2020/01/msg00025.html
- https://access.redhat.com/errata/RHSA-2020:0262
- https://access.redhat.com/errata/RHSA-2020:0274
- https://access.redhat.com/errata/RHSA-2020:0296
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XBRMI2D3XPVWKE3V52KRBW7BJVLS5LD3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LACIIDDCKZJEPKTTFILSOSBQL7L3FC6V/
- https://lists.debian.org/debian-lts-announce/2020/07/msg00008.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://github.com/uclouvain/openjpeg/issues/1228
- https://www.debian.org/security/2021/dsa-4882
More from uclouvain
View All →CVE-2025-54874
OpenJPEG allows OOB heap memory write in opj_jp2_read_header
Medium
6.6
CVE-2021-29338
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash...
Medium
5.5
CVE-2020-8112
opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a...
High
8.8
CVE-2020-15389
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can...
Medium
6.5
CVE-2019-6988
An issue was discovered in OpenJPEG 2.3.0. It allows remote...
Medium
6.5
Affected Vendor
uclouvain
View all reports →Affected Software
openjpeg, fedora, debian linux, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation, georaster, outside in technology
Vulnerable Versions:
0, 30, 31, 8.0, 9.0, 10.0, 7.0, 7.7, 8.1, 8.2, 8.4, 18c, 8.5.4, 8.5.5
Timeline
Official Publish:
January 13th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.