LWN.net Logo

openjpeg: code execution

Package(s):openjpeg CVE #(s):CVE-2012-3358
Created:July 11, 2012 Updated:July 16, 2012
Description: From the Red Hat advisory:

An input validation flaw, leading to a heap-based buffer overflow, was found in the way OpenJPEG handled the tile number and size in an image tile header. A remote attacker could provide a specially-crafted image file that, when decoded using an application linked against OpenJPEG, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application.

Alerts:
Red Hat RHSA-2012:1068-01 2012-07-11
CentOS CESA-2012:1068 2012-07-11
Mandriva MDVSA-2012:104 2012-07-12
Oracle ELSA-2012-1068 2012-07-11
Scientific Linux SL-open-20120711 2012-07-11
Mageia MGASA-2012-0165 2012-07-14
Debian DSA-2629-1 2013-02-25
Mandriva MDVSA-2013:110 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds