Vulnerability Details CVE-2018-20846
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.8%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2018-20846
-
cpe:2.3:a:uclouvain:openjpeg:-
-
cpe:2.3:a:uclouvain:openjpeg:1.0
-
cpe:2.3:a:uclouvain:openjpeg:1.1
-
cpe:2.3:a:uclouvain:openjpeg:1.2
-
cpe:2.3:a:uclouvain:openjpeg:1.3
-
cpe:2.3:a:uclouvain:openjpeg:1.4
-
cpe:2.3:a:uclouvain:openjpeg:1.5
-
cpe:2.3:a:uclouvain:openjpeg:1.5.1
-
cpe:2.3:a:uclouvain:openjpeg:1.5.2
-
cpe:2.3:a:uclouvain:openjpeg:2.0
-
cpe:2.3:a:uclouvain:openjpeg:2.0.0
-
cpe:2.3:a:uclouvain:openjpeg:2.0.1
-
cpe:2.3:a:uclouvain:openjpeg:2.1
-
cpe:2.3:a:uclouvain:openjpeg:2.1.0
-
cpe:2.3:a:uclouvain:openjpeg:2.1.1
-
cpe:2.3:a:uclouvain:openjpeg:2.1.2
-
cpe:2.3:a:uclouvain:openjpeg:2.2.0
-
cpe:2.3:a:uclouvain:openjpeg:2.3.0