Univention Bugzilla – Bug 52794
openjpeg2: Multiple issues (4.4)
Last modified: 2021-02-17 16:53:42 CET
New Debian openjpeg2 2.1.2-1.1+deb9u6 fixes: This update addresses the following issues: * Heap-buffer-overflow in lib/openjp2/mqc.c could result in DoS (CVE-2020-27814) * Heap-buffer-overflow write in lib-openjp2 (CVE-2020-27823) * global-buffer-overflow read in lib-openjp2 (CVE-2020-27824) * heap-based buffer overflows in lib/openjp2/pi.c (CVE-2020-27841) * heap-based buffer overflow in opj_t2_encode_packet function in openjp2/t2.c (CVE-2020-27844) * heap-based buffer overflow in functions opj_pi_next_rlcp, opj_pi_next_rpcl and opj_pi_next_lrcp in openjp2/pi.c (CVE-2020-27845)
--- mirror/ftp/4.4/unmaintained/4.4-6/source/openjpeg2_2.1.2-1.1+deb9u5.dsc +++ apt/ucs_4.4-0-errata4.4-7/source/openjpeg2_2.1.2-1.1+deb9u6.dsc @@ -1,3 +1,18 @@ +2.1.2-1.1+deb9u6 [Thu, 04 Feb 2021 08:18:38 +1100] Brian May <bam@debian.org>: + + * Non-maintainer upload by the LTS Security Team. + * Fix CVE-2020-27814: A heap-buffer overflow in the way openjpeg2 + handled certain PNG format files. + * Fix CVE-2020-27823: Wrong computation of x1,y1 if -d option is used, + resulting in heap buffer overflow. + * Fix CVE-2020-27824: avoid global buffer overflow on irreversible conversion when + too many decomposition levels are specified. + * Fix CVE-2020-27841: crafted input to be processed by the openjpeg encoder + could cause an out-of-bounds read. + * Fix CVE-2020-27844: crafted input to be processed by the openjpeg encoder + could cause an out-of-bounds write. + * Fix CVE-2020-27845: crafted input can cause out-of-bounds-read. + 2.1.2-1.1+deb9u5 [Fri, 10 Jul 2020 21:04:00 +0530] Utkarsh Gupta <utkarsh@debian.org>: * Non-maintainer upload by the LTS team. <http://10.200.17.11/4.4-7/#6512527586345532534>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-7] 27d1e30fd0 Bug #52794: openjpeg2 2.1.2-1.1+deb9u6 doc/errata/staging/openjpeg2.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) [4.4-7] d081b25c48 Bug #52794: openjpeg2 2.1.2-1.1+deb9u6 doc/errata/staging/openjpeg2.yaml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x897>