CVE-2023-39329
Executive Summary
OpenJPEG's opj_t1_decode_cblks in tcd.c can be triggered by a malicious JPEG to exhaust memory, causing a denial of service. The flaw allows attackers to craft an image that forces the decoder to allocate excessive resources, potentially crashing the application or system. No current KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2024-07-13T03:15:09.597 - Last Modified: 2026-09-21T18:17:03.447
Original Description: A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.
"If you love someone, set them free. If they come back they're yours; if they don't they never were."
— Richard Bach
Source: NVD