Bug #9678: openjpeg: Multiple vulnerabilities (CVE-2017-17480, CVE-2018-18088)
[3.8] openjpeg: Multiple vulnerabilities (CVE-2017-17480, CVE-2018-18088)
CVE-2018-18088: NULL pointer dereference in the imagetopnm function of jp2/convert.c¶
A flaw was found in OpenJPEG 2.3.0. A NULL pointer dereference for "red" in the
imagetopnm function of jp2/convert.c
CVE-2017-17480: Stack-buffer overflow in the pgxtovolume function¶
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability
causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.