Univention Bugzilla – Bug 51710
openjpeg2: Multiple issues (4.4)
Last modified: 2020-07-29 16:50:43 CEST
New Debian openjpeg2 2.1.2-1.1+deb9u5 fixes: This update addresses the following issues: * denial of service in function opj_t1_encode_cblks in openjp2/t1.c (CVE-2019-12973) * Heap-based buffer overflow in opj_t1_clbl_decode_processor() (CVE-2020-6851) * heap-based buffer overflow in pj_t1_clbl_decode_processor in openjp2/t1.c (CVE-2020-8112) * use-after-free and double-free via a mix of valid and invalid files in a directory operated on by the decompressor (CVE-2020-15389)
--- mirror/ftp/4.4/unmaintained/4.4-4/source/openjpeg2_2.1.2-1.1+deb9u4.dsc +++ apt/ucs_4.4-0-errata4.4-5/source/openjpeg2_2.1.2-1.1+deb9u5.dsc @@ -1,3 +1,16 @@ +2.1.2-1.1+deb9u5 [Fri, 10 Jul 2020 21:04:00 +0530] Utkarsh Gupta <utkarsh@debian.org>: + + * Non-maintainer upload by the LTS team. + * Fix CVE-2020-15389: opj_decompress: fix double-free + on input directory with mix of valid and invalid image. + * Fix CVE-2020-8112: opj_tcd_init_tile(): avoid integer + overflow. (Closes: #950184) + * Fix CVE-2020-6851: opj_j2k_update_image_dimensions(): reject + images whose coordinates are beyond INT_MAX. (Closes: #950000) + * Fix CVE-2019-12973: convertbmp: detect invalid file dimensions + early and bmp_read_rle4_data(): avoid potential infinite loop. + (Closes: #931292) + 2.1.2-1.1+deb9u4 [Tue, 08 Oct 2019 15:20:27 +0200] Hugo Lefeuvre <hle@debian.org>: * Non-maintainer upload. <http://10.200.17.11/4.4-5/#6512527586342284959>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-5] 7f18778d50 Bug #51710: openjpeg2 2.1.2-1.1+deb9u5 doc/errata/staging/openjpeg2.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) [4.4-5] dd0a059087 Bug #51710: openjpeg2 2.1.2-1.1+deb9u5 doc/errata/staging/openjpeg2.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) [4.4-5] c3c8037e73 Bug #51710: openjpeg2 2.1.2-1.1+deb9u5 doc/errata/staging/openjpeg2.yaml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x668>