---
cve: "CVE-2018-20847"
severity: "LOW"
cvss: 3.1
epss: "2.2%"
vendor: "n/a"
kev: false
exploited: false
published: "2019-06-26 18:15:10"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T09:02:17+02:00"
---

# CVE-2018-20847

> 3.1 LOW · 🧪 PoC

## Beschreibung

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

## Patch verfügbar (OSV)

- 5d00b719f4b93b1445e6fb4c766b9a9883c57949 (Commit)

## Referenzen

- <https://github.com/uclouvain/openjpeg/pull/1168/commits/c58df149900df862806d0e892859b41115875845>
- <https://github.com/uclouvain/openjpeg/commit/5d00b719f4b93b1445e6fb4c766b9a9883c57949>
- <https://github.com/uclouvain/openjpeg/issues/431>
- <http://www.securityfocus.com/bid/108921>
- <https://lists.debian.org/debian-lts-announce/2019/07/msg00010.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-20847) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
