This update fixes a denial of service vulnerability in leptonlib. It can be made to crash with an arithmetic exception on specially crafted JPEG files. For Debian 10 buster, this problem has been fixed in version . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3233-1
Several issues have been found by ClusterFuzz in leptonlib, an image processing library. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2612-1
Different flaws have been found in leptonlib, an image processing library. . Package : leptonlib Version : 1.69-3.1+deb7u2 CVE ID : CVE-2018-7186 CVE-2018-7440 Debian Bug : 890548 891932 Different flaws have been found in leptonlib, an image processing library. CVE-2018-7186 Leptonica did not limit the number of characters in a %s format argument to fscanf or sscanf, that made it possible to remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string. CVE-2018-7440 The gplotMakeOutput function allowed command injection via a $(command) approach in the gplot rootname argument. This issue existed because of an incomplete fix for CVE-2018-3836. For Debian 7 "Wheezy", these problems have been fixed in version 1.69-3.1+deb7u2. We recommend that you upgrade your leptonlib packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance leptonlib to address significant vulnerabilities that could result in denial of service and expose command injection threats.. leptonlib Security Update, Debian LTS Advisory, Command Injection Risk. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.