CVE-2018-5268: Debian Linux

Medium severity, CVSS 5.5. EPSS: 1.5% chance of exploitation in the next 30 days.

In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Opencv Opencv: version 3.3.1 only

Published 2018-01-08. Last modified 2026-06-17.