Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
197

Debian 11: DLA-4107-1 moderate: openjpeg2 denial of service

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, which could result in denial of service or the execution of arbitrary code if malformed images are processed. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4107-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany April 02, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : openjpeg2 Version : 2.4.0-3+deb11u1 CVE ID : CVE-2021-3575 CVE-2021-29338 CVE-2022-1122 CVE-2024-56826 CVE-2024-56827 Debian Bug : 989775 987276 1092675 1092676 Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, which could result in denial of service or the execution of arbitrary code if malformed images are processed. For Debian 11 bullseye, these problems have been fixed in version 2.4.0-3+deb11u1. We recommend that you upgrade your openjpeg2 packages. For the detailed security status of openjpeg2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openjpeg2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several security flaws in openjpeg2 may result in service disruption or the execution of unauthorized code. An upgrade is strongly advised.. Debian Security, openjpeg2, code execution, Denial of Service, software update. . LinuxSecurity.com Team

Calendar 2 Apr 01, 2025 Debian LTS
197

Debian 9 Stretch: DLA-2975-1 Critical: OpenJPEG2 Denial Of Service

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2020-27842 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2975-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Anton Gladky April 10, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : openjpeg2 Version : 2.1.2-1.1+deb9u7 CVE ID : CVE-2020-27842 CVE-2020-27843 CVE-2021-29338 CVE-2022-1122 Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2020-27842 Null pointer dereference through specially crafted input. The highest impact of this flaw is to application availability. CVE-2020-27843 The flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability. CVE-2021-29338 Integer overflow allows remote attackers to crash the application, causing a denial of service. This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files. CVE-2022-1122 Input directory with a large number of files can lead to a segmentation fault and a denial of service due to a call of free() on an uninitialized pointer. For Debian 9 stretch, these problems have been fixed in version 2.1.2-1.1+deb9u7. We recommend that you upgrade your openjpeg2 packages. For the detailed security status of openjpeg2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openjpeg2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update to openjpeg2 version2.1.2-1.1+deb9u7 in order to fix significant security issues impacting system stability.. Openjpeg2 Update, Debian Security Advisory, Critical Risks Resolution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 10, 2022 Critical Debian LTS
89

Fedora 25: 2016-bc8d3f1650 High: LibXYZ Memory Leak Vulnerability

Update to version 2.1.2, see https://github.com/uclouvain/openjpeg/blob/v2.1.2/CHANGELOG.md for details.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-ad1871cf02 2016-10-09 02:26:02.588643 -------------------------------------------------------------------------------- Name : openjpeg2 Product : Fedora 23 Version : 2.1.2 Release : 1.fc23 URL : https://github.com/uclouvain/openjpeg Summary : C-Library for JPEG 2000 Description : The OpenJPEG library is an open-source JPEG 2000 library developed in order to promote the use of JPEG 2000. This package contains * JPEG 2000 codec compliant with the Part 1 of the standard (Class-1 Profile-1 compliance). * JP2 (JPEG 2000 standard Part 2 - Handling of JP2 boxes and extended multiple component transforms for multispectral and hyperspectral imagery) -------------------------------------------------------------------------------- Update Information: Update to version 2.1.2, see https://github.com/uclouvain/openjpeg/blob/v2.1.2/CHANGELOG.md for details. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1377345 - CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c https://bugzilla.redhat.com/show_bug.cgi?id=1377345 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openjpeg2' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent upgrade to openjpeg2, specifically version 2.1.2, rectifies vulnerabilities associated with JPEG 2000 management within the Fedora 23 platform.. OpenJPEG Security Update,Fedora Software Management,JPEG 2000 Library. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 09, 2016 Important Fedora
89

Fedora 25 Critical Update: OpenJPEG2 Null Pointer Issue

Update to version 2.1.2, see https://github.com/uclouvain/openjpeg/blob/v2.1.2/CHANGELOG.md for details.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-0bf602e920 2016-10-09 02:40:57.478070 -------------------------------------------------------------------------------- Name : openjpeg2 Product : Fedora 25 Version : 2.1.2 Release : 1.fc25 URL : https://github.com/uclouvain/openjpeg Summary : C-Library for JPEG 2000 Description : The OpenJPEG library is an open-source JPEG 2000 library developed in order to promote the use of JPEG 2000. This package contains * JPEG 2000 codec compliant with the Part 1 of the standard (Class-1 Profile-1 compliance). * JP2 (JPEG 2000 standard Part 2 - Handling of JP2 boxes and extended multiple component transforms for multispectral and hyperspectral imagery) -------------------------------------------------------------------------------- Update Information: Update to version 2.1.2, see https://github.com/uclouvain/openjpeg/blob/v2.1.2/CHANGELOG.md for details. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1377345 - CVE-2016-7445 openjpeg2: Null pointer dereference in convert.c https://bugzilla.redhat.com/show_bug.cgi?id=1377345 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openjpeg2' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore the recent OpenJPEG library security patch in Fedora 25 addressing a crucial null pointer flaw for enhanced stability.. Fedora OpenJPEG Update, JPEG 2000 Security, Software Patch Fedora. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 09, 2016 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here