OpenJPEG before 2.3.1 has a heap buffer overflow in colorapplyicc_profile in bin/common/color.c.
{ "urgency": "not yet assigned" }