Debian alert DLA-1851-1 (openjpeg2)
From: | Markus Koschany <apo@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 1851-1] openjpeg2 security update | |
Date: | Wed, 10 Jul 2019 20:17:41 +0200 | |
Message-ID: | <ba77e139-8a5c-056a-d324-7fbd2943c0ee@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : openjpeg2 Version : 2.1.0-2+deb8u7 CVE ID : CVE-2016-9112 CVE-2018-20847 Debian Bug : 931294 844551 Two security vulnerabilities were discovered in openjpeg2, a JPEG 2000 image library. CVE-2016-9112 A floating point exception or divide by zero in the function opj_pi_next_cprl may lead to a denial-of-service. CVE-2018-20847 An improper computation of values in the function opj_get_encoding_parameters can lead to an integer overflow. This issue was partly fixed by the patch for CVE-2015-1239. For Debian 8 "Jessie", these problems have been fixed in version 2.1.0-2+deb8u7. We recommend that you upgrade your openjpeg2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl0mK8VfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeQhHA/9FIx06atS757tVz05E34Kj3UBHKq1KPPPyzliFvq1OJoCoJRFAlg7VeYM 771a61wMnqIo03B4Ng61pqRxOtgzjVha+hVfHdJwNpqutyJqL4+QU6hXm4q9fsWZ xhgiI7HSiDeI3XlrwL0TDaUpZRKezQRDM8WSCBDtzsdHIHw9FbASkvLebtfENMN0 XxxxjFQpBV1zsBo5sX/ivhqDCpQ/9vT2Mf4YO/Ia85w6mJYG3CbJ4Oq3W8mUlE4/ /YGe8KaNCJOueai9tU2q+KDTiEW8l+xCqbRRC1mvGjbOnWzEYEK5n8aAfjCJnH8/ 8wJy8fRhVbNGb4bC5i0fehhgBHNKxozA5klhkcPB2OZDDCY5bNfFeyNj+5jltGws RDyeFE3qGUga+lKSyrg9A6HwwtsIRvpRreraWahfz98OnSAkCJMnpUJeG9/w6fgo T9fETdUrCDx5UqjrAYhVOclZodECixQnJQnfS7ig9euXM7bkhNTbSyCYLSet4+oc JDKcvD1maaZcj5vVkjoksmDczJWzRxsMG0i48OqzRNeppOA/MNtx7h70Ryg1qQLn xJcAuYyflxGofhfuUAIMnI5b5iK/+q9rp98bBG31lpuoNzIl0/UWN/dWzjOviONu 0bdD8ryvTVMBw/PtNPdCVYLYPUya2T68FybTduZedNKSopClnuQ= =dXLr -----END PGP SIGNATURE-----