Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Fedora 27: 2018-a1b9eubf3d Critical: GdkPixbuf Buffer Overflow

fedora
Calendar Grey August 13, 2017
Dist Fedora Esm H88
Debian Patch Announcement for libpng highlights critical vulnerabilities concerning buffer overflows in PNG handling.
Update to version 2.2.0, see https://github.com/uclouvain/openjpeg/blob/v2.2.0/NEWS.md for details.

Summary

The OpenJPEG library is an open-source JPEG 2000 library developed in order to

promote the use of JPEG 2000.

This package contains

* JPEG 2000 codec compliant with the Part 1 of the standard (Class-1 Profile-1

compliance).

* JP2 (JPEG 2000 standard Part 2 - Handling of JP2 boxes and extended multiple

component transforms for multispectral and hyperspectral imagery)

Update to version 2.2.0, see

https://github.com/uclouvain/openjpeg/blob/v2.2.0/NEWS.md for details.

[ 1 ] Bug #1390234 - CVE-2016-9112 CVE-2016-9113 CVE-2016-9114 CVE-2016-9115 CVE-2016-9116 CVE-2016-9117 CVE-2016-9118 openjpeg2: Multiple security issues [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1390234

[ 2 ] Bug #1435072 - CVE-2016-5139 openjpeg2: chromium-browser, openjpeg: Heap overflow in parsing of JPEG2000 precincts [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1435072

[ 3 ] Bug #1435071 - CVE-2016-5158 openjpeg2: chromium-browser, openjpeg: heap overflow due to unsafe use of opj_aligned_malloc [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1435071

[ 4 ] Bug #1435070 - CVE-2016-5159 openjpeg2: chromium-browser, openjpeg: heap overflow in parsing of JPEG2000 code blocks [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1435070

[ 5 ] Bug #1418150 - CVE-2016-9112 openjpeg2: Floating point exception vulnerability in openjpeg2 when processing untrusted images [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1418150

su -c 'dnf upgrade openjpeg2' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 2.2.0
Release: 1.fc26
Summary: C-Library for JPEG 2000

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here