CVE-2018-20845: Uclouvain Openjpeg

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

Affected products

  • Uclouvain Openjpeg: up to and including 2.3.0

Published 2019-06-26. Last modified 2026-06-17.