Multiple out-of-bounds error were discovered in qt4-x11. The highest threat from CVE-2021-3481 (at least) is to data confidentiality the application availability. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2895-1
Multiple out-of-bounds error were discovered in qtsvg-opensource-src. The highest threat from CVE-2021-3481 (at least) is to data confidentiality the application availability. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2885-1
There's a flaw in openjpeg in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability (CVE-2020-27841). . MGASA-2020-0478 - Updated openjpeg2 packages fix security vulnerabilities Publication date: 29 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0478.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-27841, CVE-2020-27842, CVE-2020-27843, CVE-2020-27845 There's a flaw in openjpeg in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability (CVE-2020-27841). There's a flaw in openjpeg's t2 encoder. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability (CVE-2020-27842). A flaw was found in OpenJPEG. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability (CVE-2020-27843). There's a flaw in src/lib/openjp2/pi.c of openjpeg. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw is to application availability (CVE-2020-27845). References: - https://bugs.mageia.org/show_bug.cgi?id=27903 - https://lists.fedoraproject.org/archives/list/
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability (CVE-2020-27828). . MGASA-2020-0463 - Updated jasper packages fix security vulnerability Publication date: 17 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0463.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-27828 There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability (CVE-2020-27828). References: - https://bugs.mageia.org/show_bug.cgi?id=27842 - https://github.com/jasper-software/jasper/releases/tag/version-2.0.23 - https://www.cve.org/CVERecord?id=CVE-2020-27828 SRPMS: - 7/core/jasper-2.0.23-1.mga7 . An issue in Jasper's encoder may jeopardize data reliability and accessibility on Mageia. Ensure you upgrade to protect your system.. Jasper Security Update,Mageia Security Advisory,Data Integrity Risk. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.