Heap-based buffer overflow in the colorcmykto_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
{ "urgency": "not yet assigned" }