CVE-2017-17480
Write stack buffer overflow in the jp3d and jpwl codecs can result
in a denial of service or remote code execution via a crafted jp3d
or jpwl file.
CVE-2018-5785
Integer overflow can result in a denial of service via a crafted bmp
file.
CVE-2018-6616
Excessive iteration can result in a denial of service via a crafted
bmp file.
CVE-2018-14423
Division-by-zero vulnerabilities can result in a denial of service via
a crafted j2k file.
CVE-2018-18088
Null pointer dereference can result in a denial of service via a
crafted bmp file.
For the stable distribution (stretch), these problems have been fixed in
version 2.1.2-1.1+deb9u3.
We recommend that you upgrade your openjpeg2 packages.
For the detailed security status of openjpeg2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/openjpeg2
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently as...
Get the latest Linux and open source security news straight to your inbox.