Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Required
Privileges Required
None
Attack Vector
Local
0

CVE-2020-27842

Disclosure Date: January 05, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

There’s a flaw in openjpeg’s t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
5.5 Medium
Impact Score:
3.6
Exploitability Score:
1.8
Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
Required
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • debian,
  • fedoraproject,
  • oracle,
  • redhat,
  • uclouvain

Products

  • codeready linux builder 8.0,
  • codeready linux builder for ibm z systems 8.0,
  • codeready linux builder for power little endian 8.0,
  • debian linux 10.0,
  • debian linux 9.0,
  • enterprise linux 8.0,
  • enterprise linux for ibm z systems 8.0,
  • enterprise linux for power little endian 8.0,
  • extra packages for enterprise linux 7.0,
  • fedora 32,
  • fedora 33,
  • openjpeg,
  • outside in technology 8.5.5
Technical Analysis