CVE-2019-12973

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-12973
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12973.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-12973
Downstream
Related
Published
2019-06-26T18:15:10Z
Modified
2025-10-10T01:40:50.431218Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In OpenJPEG 2.3.1, there is excessive iteration in the opjt1encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

References

Affected packages

Git / github.com/uclouvain/openjpeg

Affected ranges

Type
GIT
Repo
https://github.com/uclouvain/openjpeg
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v2.*

v2.2.0
v2.3.0

Database specific

{
    "vanir_signatures": [
        {
            "id": "CVE-2019-12973-35e0ec8a",
            "digest": {
                "length": 1399.0,
                "function_hash": "81929091039132960155780805690430238765"
            },
            "target": {
                "function": "bmp_read_rle8_data",
                "file": "src/bin/jp2/convertbmp.c"
            },
            "source": "https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67b11ec3",
            "signature_version": "v1",
            "deprecated": false,
            "signature_type": "Function"
        },
        {
            "id": "CVE-2019-12973-83778897",
            "digest": {
                "line_hashes": [
                    "77636936433144648117381511526191110653",
                    "183302273827641616826540289135523153428",
                    "65269223957392472433334701979460511267",
                    "59707955247167473863662549267590613949",
                    "322298667671987638395076744301206986377",
                    "232404145414626107981458196450651320968",
                    "289458997193636776763867888812167293327",
                    "13384536911047527457182828460160666900",
                    "46871980493215975922026015114378524541",
                    "144104948709376102765644926628207135645",
                    "295170891517319101389231089439069449359",
                    "252787013674851661264041490130253976418",
                    "107250163831291265973788838952952422966",
                    "250245717910178570951424657858112863088",
                    "93537647608255735541413567565670746666",
                    "228234405337706127464700532848322466791",
                    "264929650207890875718971684201152659841",
                    "108587633537507210242609878158511307392",
                    "241166423729958240998350858258662147156",
                    "169443768931054359674620264080578889195",
                    "120751972370044129218675960987130825278"
                ],
                "threshold": 0.9
            },
            "target": {
                "file": "src/bin/jp2/convertbmp.c"
            },
            "source": "https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67b11ec3",
            "signature_version": "v1",
            "deprecated": false,
            "signature_type": "Line"
        }
    ]
}