CVE-2018-20845
Publication date 26 June 2019
Last updated 11 July 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
From the Ubuntu Security Team
It was discovered that OpenJPEG incorrectly handled certain image files. A remote attacker could possibly use this issue to cause a denial of service.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| emscripten | 25.10 questing | Ignored | 
| 25.04 plucky | Ignored | |
| 24.04 LTS noble | Ignored | |
| 22.04 LTS jammy | Ignored | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Ignored | |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Not in release | |
| qtwebengine-opensource-src | 25.10 questing | 
                                Needs evaluation 
                                
                               | 
| 25.04 plucky | 
                                Needs evaluation 
                                
                               | |
| 24.04 LTS noble | 
                                Needs evaluation 
                                
                               | |
| 22.04 LTS jammy | 
                                Needs evaluation 
                                
                               | |
| 20.04 LTS focal | 
                                Needs evaluation 
                                
                               | |
| 18.04 LTS bionic | 
                                Needs evaluation 
                                
                               | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| texmaker | 25.10 questing | 
                                Needs evaluation 
                                
                               | 
| 25.04 plucky | 
                                Needs evaluation 
                                
                               | |
| 24.04 LTS noble | 
                                Needs evaluation 
                                
                               | |
| 22.04 LTS jammy | 
                                Needs evaluation 
                                
                               | |
| 20.04 LTS focal | 
                                Needs evaluation 
                                
                               | |
| 18.04 LTS bionic | 
                                Needs evaluation 
                                
                               | |
| 16.04 LTS xenial | 
                                Needs evaluation 
                                
                               | |
| 14.04 LTS trusty | Not in release | |
| blender | 25.10 questing | 
                                Needs evaluation 
                                
                               | 
| 25.04 plucky | 
                                Needs evaluation 
                                
                               | |
| 24.04 LTS noble | 
                                Needs evaluation 
                                
                               | |
| 22.04 LTS jammy | 
                                Needs evaluation 
                                
                               | |
| 20.04 LTS focal | 
                                Needs evaluation 
                                
                               | |
| 18.04 LTS bionic | 
                                Needs evaluation 
                                
                               | |
| 16.04 LTS xenial | 
                                Needs evaluation 
                                
                               | |
| 14.04 LTS trusty | Not in release | |
| insighttoolkit4 | 25.10 questing | Not in release | 
| 25.04 plucky | Not in release | |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | 
                                Needs evaluation 
                                
                               | |
| 20.04 LTS focal | 
                                Needs evaluation 
                                
                               | |
| 18.04 LTS bionic | 
                                Needs evaluation 
                                
                               | |
| 16.04 LTS xenial | 
                                Needs evaluation 
                                
                               | |
| 14.04 LTS trusty | Not in release | |
| openjpeg | 25.10 questing | Not in release | 
| 25.04 plucky | Not in release | |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | 
                                Not affected 
                                
                               | |
| 14.04 LTS trusty | 
                                Not affected 
                                
                               | |
| gdcm | 25.10 questing | 
                                Not affected 
                                
                               | 
| 25.04 plucky | 
                                Not affected 
                                
                               | |
| 24.04 LTS noble | 
                                Not affected 
                                
                               | |
| 22.04 LTS jammy | 
                                Not affected 
                                
                               | |
| 20.04 LTS focal | 
                                Not affected 
                                
                               | |
| 18.04 LTS bionic | 
                                Not affected 
                                
                               | |
| 16.04 LTS xenial | 
                                Not affected 
                                
                               | |
| 14.04 LTS trusty | 
                                Not affected 
                                
                               | |
| openjpeg2 | 25.10 questing | 
                                Not affected 
                                
                               | 
| 25.04 plucky | 
                                Not affected 
                                
                               | |
| 24.04 LTS noble | 
                                Not affected 
                                
                               | |
| 22.04 LTS jammy | 
                                Not affected 
                                
                               | |
| 20.04 LTS focal | 
                                Not affected 
                                
                               | |
| 18.04 LTS bionic | 
                                Fixed 2.3.0-2ubuntu0.1~esm1 
                                
                                   | |
| 16.04 LTS xenial | 
                                Not affected 
                                
                               | |
| 14.04 LTS trusty | Not in release | 
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
ebarretto
Marking emscripten ignored as openjpeg2 code is only for test/example.
mdeslaur
Ubuntu openjpeg2 packages are built with BUILD_MJ2:BOOL=OFF, so the vulnerable code is not compiled
ccdm94
the openjpeg package does not include the file patched by commit c5bd64ea146. Before the refactoring, there was a single pi.c file, which according to the code itself, seems to be affected by this vulnerability, however, it looks like the vulnerability in this case is related to CVE-2018-14423 instead, which has a very similar patch (bd88611ed9a).
Patch details
| Package | Patch details | 
|---|---|
| openjpeg | |
| openjpeg2 | 
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score |  | 
| Attack vector | Network | 
| Attack complexity | Low | 
| Privileges required | None | 
| User interaction | Required | 
| Scope | Unchanged | 
| Confidentiality | None | 
| Integrity impact | None | 
| Availability impact | High | 
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H | 
References
Related Ubuntu Security Notices (USN)
- USN-4782-1
- OpenJPEG vulnerabilities
- 17 March 2021