PublicDateAtUSN: 2018-02-04 Candidate: CVE-2018-6616 PublicDate: 2018-02-04 22:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6616 https://github.com/uclouvain/openjpeg/issues/1059 https://ubuntu.com/security/notices/USN-4109-1 Description: In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_openjpeg2: upstream_openjpeg2: released (2.3.0-2) precise/esm_openjpeg2: DNE trusty_openjpeg2: DNE trusty/esm_openjpeg2: DNE xenial_openjpeg2: released (2.1.2-1.1+deb9u3build0.16.04.1) artful_openjpeg2: ignored (reached end-of-life) bionic_openjpeg2: released (2.3.0-2build0.18.04.1) cosmic_openjpeg2: ignored (reached end-of-life) disco_openjpeg2: not-affected (2.3.0-2) devel_openjpeg2: not-affected (2.3.0-2)