The bmpreadinfoheader function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opjimagecreate function in lib/openjp2/image.c, related to the opjalignedallocn function in opj_malloc.c.
{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.3.0"
}
],
"cpe": "cpe:2.3:a:uclouvain:openjpeg:*:*:*:*:*:*:*:*"
}