- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2612-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
March 31, 2021                                https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : leptonlib
Version        : 1.74.1-1+deb9u1
CVE ID         : CVE-2020-36277 CVE-2020-36278 CVE-2020-36279
                  CVE-2020-36281


Several issues have been found by ClusterFuzz in leptonlib, an image 
processing library.

All issues are related to heap-based buffer over-read in several functions 
or a denial of service (application crash) with crafted data.


For Debian 9 stretch, these problems have been fixed in version
1.74.1-1+deb9u1.

We recommend that you upgrade your leptonlib packages.

For the detailed security status of leptonlib please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/leptonlib

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2612-1: leptonlib security update

March 31, 2021
Several issues have been found by ClusterFuzz in leptonlib, an image processing library

Summary

Several issues have been found by ClusterFuzz in leptonlib, an image
processing library.

All issues are related to heap-based buffer over-read in several functions
or a denial of service (application crash) with crafted data.


For Debian 9 stretch, these problems have been fixed in version
1.74.1-1+deb9u1.

We recommend that you upgrade your leptonlib packages.

For the detailed security status of leptonlib please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/leptonlib

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
Package : leptonlib
Version : 1.74.1-1+deb9u1
CVE ID : CVE-2020-36277 CVE-2020-36278 CVE-2020-36279

Related News