openjpeg: heap-based buffer overflow in opj_t2_encode_packet function in openjp2/t2.c (CVE-2020-27844)
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
References:
Patch:
https://github.com/uclouvain/openjpeg/commit/73fdf28342e4594019af26eb6a347a34eceb6296
Affected branches:
Edited by Francesco Colista