The color_esycc_to_rgb function in bin/common/color.c in OpenJPEG before 2.1.1 allows attackers to cause a denial of service (memory corruption) via a crafted jpeg 2000 file. CREATE(Triage):(User=admin) CVE-2016-3182 (https://nvd.nist.gov/vuln/detail/CVE-2016-3182)