Heap-based buffer overflow in PhotoLine 17.01 and possibly other versions before 17.02 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
https://exchange.xforce.ibmcloud.com/vulnerabilities/73103
http://www.securityfocus.com/bid/51948