CVE-2009-5030

The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:uclouvain:openjpeg:1.3:*:*:*:*:*:*:*
cpe:2.3:a:uclouvain:openjpeg:1.4:*:*:*:*:*:*:*
cpe:2.3:a:uclouvain:openjpeg:1.5:*:*:*:*:*:*:*

History

13 Feb 2023, 02:20

Type Values Removed Values Added
References
  • {'url': 'https://groups.google.com/forum/#!topic/openjpeg/DLVrRKbTeI0/discussion', 'name': 'https://groups.google.com/forum/#!topic/openjpeg/DLVrRKbTeI0/discussion', 'tags': [], 'refsource': 'CONFIRM'}
  • (MISC) https://groups.google.com/forum/#%21topic/openjpeg/DLVrRKbTeI0/discussion -

Information

Published : 2012-07-18 22:55

Updated : 2023-12-10 11:16


NVD link : CVE-2009-5030

Mitre link : CVE-2009-5030

CVE.ORG link : CVE-2009-5030


JSON object : View

Products Affected

uclouvain

  • openjpeg
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer