CVE-2016-9115 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9115): Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Affects CLI tool only.
As said multiple times by mitre, a read overflow in a command-line tool where no library are involved is considered an inconvenience instead of a security issue.