In OpenJPEG 2.3.1, there is excessive iteration in the opjt1encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
{ "vanir_signatures": [ { "id": "CVE-2019-12973-35e0ec8a", "digest": { "length": 1399.0, "function_hash": "81929091039132960155780805690430238765" }, "target": { "function": "bmp_read_rle8_data", "file": "src/bin/jp2/convertbmp.c" }, "source": "https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67b11ec3", "signature_version": "v1", "deprecated": false, "signature_type": "Function" }, { "id": "CVE-2019-12973-83778897", "digest": { "line_hashes": [ "77636936433144648117381511526191110653", "183302273827641616826540289135523153428", "65269223957392472433334701979460511267", "59707955247167473863662549267590613949", "322298667671987638395076744301206986377", "232404145414626107981458196450651320968", "289458997193636776763867888812167293327", "13384536911047527457182828460160666900", "46871980493215975922026015114378524541", "144104948709376102765644926628207135645", "295170891517319101389231089439069449359", "252787013674851661264041490130253976418", "107250163831291265973788838952952422966", "250245717910178570951424657858112863088", "93537647608255735541413567565670746666", "228234405337706127464700532848322466791", "264929650207890875718971684201152659841", "108587633537507210242609878158511307392", "241166423729958240998350858258662147156", "169443768931054359674620264080578889195", "120751972370044129218675960987130825278" ], "threshold": 0.9 }, "target": { "file": "src/bin/jp2/convertbmp.c" }, "source": "https://github.com/uclouvain/openjpeg/commit/8ee335227bbcaf1614124046aa25e53d67b11ec3", "signature_version": "v1", "deprecated": false, "signature_type": "Line" } ] }