Impact
An incorrect handling of parameters in the JP2 encoder can trigger a heap buffer over-write, corrupting memory adjacent to the buffer. This vulnerabilityCWE-682) and a buffer overflow (CWE-787). The corruption may lead to application crashes or other disruptive behaviors when a specially crafted JPEG-2000 image is processed.
Affected Systems
All installations prior to version 7.1.2-26 are vulnerable. Only systems that ingest or manipulate JPEG-2000 images with the affected library are affected.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity. The EPSS score of < 1% suggests a low probability of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the likely attack vector, the delivery of a malicious JP2 image to an ImageMagick process, either locally or through a service that accepts untrusted image files, could lead to memory corruption resulting in crashes or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA