LWN.net Logo

openjpeg: code execution

Package(s):openjpeg CVE #(s):CVE-2012-3535
Created:September 17, 2012 Updated:November 2, 2012
Description: From the Red Hat advisory:

It was found that OpenJPEG failed to sanity-check an image header field before using it. A remote attacker could provide a specially-crafted image file that could cause an application linked against OpenJPEG to crash or, possibly, execute arbitrary code.

Alerts:
Red Hat RHSA-2012:1283-01 2012-09-17
CentOS CESA-2012:1283 2012-09-17
Scientific Linux SL-open-20120917 2012-09-17
Oracle ELSA-2012-1283 2012-09-17
Mageia MGASA-2012-0274 2012-09-18
Mandriva MDVSA-2012:157 2012-10-03
openSUSE openSUSE-SU-2012:1370-1 2012-10-19
Fedora FEDORA-2012-14707 2012-10-23
Fedora FEDORA-2012-14717 2012-11-02
Debian DSA-2629-1 2013-02-25
Mandriva MDVSA-2013:110 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds