{"id":"CVE-2018-5268","details":"In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.","aliases":["GHSA-9g8h-pjm4-q92p"],"modified":"2026-04-10T04:10:52.796261Z","published":"2018-01-08T05:29:00.320Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106945"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/04/msg00019.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/07/msg00030.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2021/10/msg00028.html"},{"type":"REPORT","url":"https://github.com/opencv/opencv/issues/10541"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencv/opencv","events":[{"introduced":"0"},{"last_affected":"af4d6f34d8d05b0a9a0278728823272e49a63898"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"3.3.1"}]}}],"versions":["2.2","3.2.0-rc","3.3.0-rc","3.3.1-cvsdk"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-5268.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}