Lucene search

K
redhatcveRedhat.comRH:CVE-2018-21010
HistorySep 26, 2019 - 8:20 a.m.

CVE-2018-21010

2019-09-2608:20:53
redhat.com
access.redhat.com
16

0.008 Low

EPSS

Percentile

81.9%

A heap-based buffer overflow has been discovered in OpenJPEG in the function color_apply_icc_profile, while applying the color transformation. An application that uses OpenJPEG to parse untrusted images may be vulnerable to this flaw, which would allow an attacker to crash the application or potentially execute code.

Mitigation

If the application accepts untrusted images there is no known mitigation apart from applying the patch.