CVE-2017-14152 describes a heap-based buffer overflow vulnerability in OpenJPEG 2.2.0, specifically within the opj_j2k_set_cinema_parameters function, affecting Debian and UCLouvain distributions. This flaw, due to a mishandled zero case, can lead to remote denial of service or potentially remote code execution. With a CVSS score of 8.8 (High), it can be exploited remotely with low attack complexity, requiring user interaction, and has high impacts on confidentiality, integrity, and availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the CISA KEV catalog, indicating no active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0CPE matchmatch criteria | cpe:2.3:a:uclouvain:openjpeg:2.2.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.