Back

CVE-2017-17480

CRITICAL

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

Published: Dec 8, 2017 Modified: Jun 17, 2026
CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
uclouvain openjpeg 2.3.0
debian debian_linux 8.0
debian debian_linux 9.0
canonical ubuntu_linux 18.04

GitHub Security Advisory GHSA-j9x9-9h4c-f6v6

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.14%

Top 8% most likely to be exploited

Threat Score 40.7 / 100

Data Sources

NVD EPSS GitHub