{
  "threat_severity" : "Moderate",
  "public_date" : "2020-11-23T00:00:00Z",
  "bugzilla" : {
    "description" : "openjpeg: heap-buffer-overflow in lib/openjp2/mqc.c could result in DoS",
    "id" : "1901998",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1901998"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-122",
  "details" : [ "A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application.", "A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application." ],
  "acknowledgement" : "Red Hat would like to thank zodf0055980 (SQLab NCTU Taiwan) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2021-11-09T00:00:00Z",
    "advisory" : "RHSA-2021:4251",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "openjpeg2-0:2.4.0-4.el8"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "openjpeg",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "openjpeg",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Will not fix",
    "package_name" : "openjpeg2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-27814\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-27814\nhttps://github.com/uclouvain/openjpeg/issues/1283" ],
  "name" : "CVE-2020-27814",
  "csaw" : false
}