CVE-2018-21010: Debian Linux

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Uclouvain Openjpeg: before 2.3.1 (fixed in 2.3.1)

Published 2019-09-05. Last modified 2026-06-17.