CVE-2018-20847: Debian Linux

High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Uclouvain Openjpeg: up to and including 2.3.0

Published 2019-06-26. Last modified 2026-06-17.