New Debian openjpeg2 2.5.0-2+deb12u1 fixes: This update addresses the following issues: * openjpeg: heap-buffer-overflow in color.c may lead to DoS or arbitrary code execution (CVE-2021-3575) * openjpeg: Malicious files can cause the program to enter a large loop (CVE-2023-39327) * openjpeg: heap buffer overflow in bin/common/color.c (CVE-2024-56826) * openjpeg: heap buffer overflow in lib/openjp2/j2k.c (CVE-2024-56827)
--- mirror/ftp/pool/main/o/openjpeg2/openjpeg2_2.5.0-2.dsc +++ apt/ucs_5.2-0-errata5.2-0/source/openjpeg2_2.5.0-2+deb12u1.dsc @@ -1,3 +1,10 @@ +2.5.0-2+deb12u1 [Fri, 24 Jan 2025 17:47:06 +0100] Moritz Mühlenhoff <jmm@debian.org>: + + * CVE-2021-3575 (Closes: #989775) + * CVE-2023-39327 (Closes: #1081908) + * CVE-2024-56826 (Closes: #1092675) + * CVE-2024-56827 (Closes: #1092675) + 2.5.0-2 [Fri, 26 May 2023 12:16:24 +0200] Andreas Metzler <ametzler@debian.org>: * Team upload. <http://piuparts.knut.univention.de/5.2-0/#3711021940567611469>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-0] 5596f0c03c Bug #57928: openjpeg2 2.5.0-2+deb12u1 doc/errata/staging/openjpeg2.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x13>