CVE-2018-18088: Debian Linux

Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.

OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Uclouvain Openjpeg: version 2.3.0 only

Published 2018-10-09. Last modified 2026-06-17.