CVE-2017-2811
Last modified
CVE-2017-2811 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.. EPSS estimates a 1.56% chance of exploitation in the next 30 days.
Description
A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kakadusoftware | Kakadu Sdk | 7.9 |
References
- https://www.securityfocus.com/bid/100141Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0308Third Party Advisory
- https://www.securityfocus.com/bid/100141Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0308Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2811?
How severe is CVE-2017-2811?
How do I fix CVE-2017-2811?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-2805An exploitable stack-based buffer overflow vulnerability exi…9.8
- CVE-2017-2806An exploitable arbitrary read exists in the XLS parsing of t…4.3
- CVE-2017-2807An exploitable buffer overflow vulnerability exists in the t…7.5
- CVE-2017-2808An exploitable use-after-free vulnerability exists in the ac…7.5
- CVE-2017-2809An exploitable vulnerability exists in the yaml loading func…7.5
- CVE-2017-2810An exploitable vulnerability exists in the Databook loading …7.5
- CVE-2017-2812A code execution vulnerability exists in the kdu_buffered_ex…8.8
- CVE-2017-2813An exploitable integer overflow vulnerability exists in the …8.8
- CVE-2017-2814An exploitable heap overflow vulnerability exists in the ima…7.5
- CVE-2017-2815An exploitable XML entity injection vulnerability exists in …8.1
- CVE-2017-2816An exploitable buffer overflow vulnerability exists in the t…8.8
- CVE-2017-2817A stack buffer overflow vulnerability exists in the ISO pars…8.8
Are you affected by CVE-2017-2811?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
