Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 8: DLA-1851-1 Moderate: openjpeg2 Denial of Service and Overflow

debian lts
Calendar Grey July 10, 2019
Dist Debian Esm H88
Enhance your openjpeg2 installations to address various vulnerabilities, such as denial of service threats and potential integer overflow problems.
Two security vulnerabilities were discovered in openjpeg2, a JPEG 2000 image library

Summary

A floating point exception or divide by zero in the function
opj_pi_next_cprl may lead to a denial-of-service.

CVE-2018-20847

An improper computation of values in the function
opj_get_encoding_parameters can lead to an integer overflow.
This issue was partly fixed by the patch for CVE-2015-1239.

For Debian 8 "Jessie", these problems have been fixed in version
2.1.0-2+deb8u7.

We recommend that you upgrade your openjpeg2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: openjpeg2
Version: 2.1.0-2+deb8u7
CVE ID: CVE-2016-9112 CVE-2018-20847
Debian Bug: 931294 844551

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here