Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA-2808-1 Serious: OpenJPEG Denial Of Service Threats

debian
Calendar Grey December 3, 2013
Debian Logo
Keep current with essential OpenJPEG news since security flaws might cause operational issues. Update advised.
Several vulnerabilities have been discovered in OpenJPEG, a JPEG 2000 image library, that may lead to denial of service (CVE-2013-1447) via application crash or high memory consump...

Summary

Several vulnerabilities have been discovered in OpenJPEG, a JPEG 2000
image library, that may lead to denial of service (CVE-2013-1447) via
application crash or high memory consumption, possible code execution
through heap buffer overflows (CVE-2013-6045), information disclosure
(CVE-2013-6052), or yet another heap buffer overflow that only appearsto affect OpenJPEG 1.3 (CVE-2013-6054).

For the oldstable distribution (squeeze), these problems have been fixed in
version 1.3+dfsg-4+squeeze2.

For the stable distribution (wheezy), these problems have been fixed in
version 1.3+dfsg-4.7.

For the testing distribution (jessie), and the unstable distribution (sid),
these problems will be fixed soon.

We recommend that you upgrade your openjpeg packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: openjpeg
CVE ID: CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 CVE-2013-6054

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here