CVE-2018-18088: Null Pointer Dereference
Last updated 26 August 2025
Other sources
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openjpeg2to a version that resolves this vulnerability.Fixed in 2.3.0-2Fixed in 2.1.2-1.1+deb9u3 - Upgrade
Upgrade
debian/openjpeg2to a version that resolves this vulnerability.Fixed in 2.4.0-3Fixed in 2.4.0-3+deb11u3Fixed in 2.5.0-2+deb12u3Fixed in 2.5.3-2.1~deb13u2Fixed in 2.5.4-1.1
Event History
Frequently Asked Questions
What is CVE-2018-18088?
CVE-2018-18088 is a vulnerability in OpenJPEG 2.3.0 that allows for a NULL pointer dereference in the imagetopnm function of jp2/convert.c.
What is the severity of CVE-2018-18088?
The severity of CVE-2018-18088 is medium with a severity value of 6.5.
How does CVE-2018-18088 affect OpenJPEG?
CVE-2018-18088 affects OpenJPEG version 2.3.0.
How can I fix CVE-2018-18088?
You can fix CVE-2018-18088 by updating OpenJPEG to version 2.3.0-2 or applying the recommended patches from the respective sources.
Where can I find more information about CVE-2018-18088?
You can find more information about CVE-2018-18088 on the GitHub issue page, Debian security tracker page, and MITRE CVE page.