Mageia alert MGASA-2020-0074 (openjpeg2)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2020-0074: Updated openjpeg2 packages fix security vulnerability | |
| Date: | Tue, 4 Feb 2020 12:08:15 +0100 | |
| Message-ID: | <20200204110815.76A5A9F641@duvel.mageia.org> |
MGASA-2020-0074 - Updated openjpeg2 packages fix security vulnerability Publication date: 04 Feb 2020 URL: https://advisories.mageia.org/MGASA-2020-0074.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-8112 Description: opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851. (CVE-2020-8112) References: - https://bugs.mageia.org/show_bug.cgi?id=26162 - https://www.debian.org/lts/security/2020/dla-2089 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8112 SRPMS: - 7/core/openjpeg2-2.3.1-1.3.mga7
