CVE-2018-7648: Uclouvain Openjpeg
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.
Affected products
- Uclouvain Openjpeg: version 2.3.0 only
Published 2018-03-02. Last modified 2026-06-17.