CVE-2023-39329
Medium
|6.5No Exploit
Plain English Summary
AI-powered analysis for quick understanding
An attacker can create a specially crafted image file that, when processed by OpenJPEG, can overwhelm the system's resources and cause it to crash, leading to a denial of service. This vulnerability requires the target system to open the malicious image file for the attack to succeed.
Technical Description
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh
ScopeUnchanged
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$931($500-$1K)
Vendor Response
Grade FPatched in 604 days
Quick Information
Published
Jul 13, 2024
over 1 year ago
Last Modified
Mar 9, 2026
29 days ago
Vendor
uclouvain
Product
openjpeg