Mageia 2021-0093: openjpeg2 security update
Summary
A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0.
This flaw allows an attacker to provide crafted input to openjpeg during
conversion and encoding, causing an out-of-bounds write. The highest threat
from this vulnerability is to confidentiality, integrity, as well as system
availability. (CVE-2020-27844).
References
- https://bugs.mageia.org/show_bug.cgi?id=27986
- https://www.debian.org/lts/security/2021/dla-2550
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27844
Resolution
MGASA-2021-0093 - Updated openjpeg2 packages fix security vulnerability
SRPMS
- 7/core/openjpeg2-2.4.0-1.mga7