CVE-2020-6851

Executive Summary

OpenJPEG 2.3.1 and earlier contain a heap‑based buffer overflow in opj_t1_clbl_decode_processor due to missing validation of image dimensions during JPEG 2000 decoding. An attacker can supply a crafted JPEG 2000 file to overflow a buffer, potentially leading to arbitrary code execution or denial of service. The vulnerability is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2020-01-13T06:15:10.957 - Last Modified: 2026-09-22T18:17:08.367

Original Description: OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

"I have been impressed with the urgency of doing. Knowing is not enough; we must apply. Being willing is not enough; we must do."

— Leonardo da Vinci
Source: NVD