CVE-2024-0144 Details
Description
NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a buffer overflow issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to data tampering.
A heap-based buffer overflow vulnerability has been identified in the NVIDIA nvJPEG2000 library version 0.8.0. This vulnerability arises in the Ndecomp field handling, where a specially crafted JPEG2000 file can overwrite adjacent heap memory. Such an exploit could lead to memory corruption and arbitrary code execution.
Users are advised to upgrade to NVIDIA nvJPEG2000 version 0.8.1, available on the NVIDIA Developer nvJPEG2000 Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 12, 2025CISA-ADP
Assessed Apr 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2108 | CVE | ExploitTechnical Analysis |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2113 | CVE | ExploitTechnical Analysis |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5596 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NVIDIA nvJPEG2000 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2025 | CVE Modified | CVE |
| Feb 12, 2025 | CVE Modified | CVE |
| Feb 12, 2025 | New CVE Received | [email protected] |
Volerion