Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 27: Security Advisory for OpenJPEG2 Critical Heap Overflow

fedora
Calendar Grey September 30, 2017
Dist Fedora Esm H88
This patch resolves several security flaws identified in the openjpeg2 package for Fedora 27.
This update fixes CVE-2017-12982, CVE-2017-14040, CVE-2017-14041 and two other security vulnerabilities.

Summary

The OpenJPEG library is an open-source JPEG 2000 library developed in order to

promote the use of JPEG 2000.

This package contains

* JPEG 2000 codec compliant with the Part 1 of the standard (Class-1 Profile-1

compliance).

* JP2 (JPEG 2000 standard Part 2 - Handling of JP2 boxes and extended multiple

component transforms for multispectral and hyperspectral imagery)

This update fixes CVE-2017-12982, CVE-2017-14040, CVE-2017-14041 and two other

security vulnerabilities.

[ 1 ] Bug #1487236 - CVE-2017-12982 openjpeg: Memory allocation failure in the opj_image_create function

https://bugzilla.redhat.com/show_bug.cgi?id=1487236

[ 2 ] Bug #1487347 - CVE-2017-14041 openjpeg: Stack-based buffer over-write in pgxtoimage function in bin/jp2/convert.c

https://bugzilla.redhat.com/show_bug.cgi?id=1487347

[ 3 ] Bug #1487361 - CVE-2017-14040 openjpeg: Invalid write access in bin/jp2/convert.c

https://bugzilla.redhat.com/show_bug.cgi?id=1487361

[ 4 ] Bug #1487389 - CVE-2017-14152 openjpeg: Heap-based buffer overflow in opj_write_bytes_LE in cio.c

https://bugzilla.redhat.com/show_bug.cgi?id=1487389

[ 5 ] Bug #1487390 - CVE-2017-14151 openjpeg: Heap-based buffer overflow in opj_mqc_flush in mqc.c

https://bugzilla.redhat.com/show_bug.cgi?id=1487390

su -c 'dnf upgrade openjpeg2' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 2.2.0
Release: 3.fc27
Summary: C-Library for JPEG 2000

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here