Medium severity5.5NVD Advisory· Published Aug 21, 2017· Updated May 13, 2026
CVE-2017-12982
CVE-2017-12982
Description
The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- blogs.gentoo.org/ago/2017/08/14/openjpeg-memory-allocation-failure-in-opj_aligned_alloc_n-opj_malloc-c/nvdPatchThird Party AdvisoryVDB Entry
- github.com/uclouvain/openjpeg/commit/baf0c1ad4572daa89caa3b12985bdd93530f0dd7nvdIssue TrackingPatchThird Party Advisory
- github.com/uclouvain/openjpeg/issues/983nvdIssue TrackingPatchThird Party Advisory
- security.gentoo.org/glsa/201710-26nvdThird Party Advisory
News mentions
0No linked articles in our index yet.