Debian Security Advisory
DSA-2629-1 openjpeg -- several issues
- Date Reported:
- 25 Feb 2013
- Affected Packages:
- openjpeg
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 672455, Bug 681075, Bug 685970.
In Mitre's CVE dictionary: CVE-2009-5030, CVE-2012-3358, CVE-2012-3535. - More information:
-
- CVE-2009-5030
Heap memory corruption leading to invalid free when processing certain Gray16 TIFF images.
- CVE-2012-3358
Huzaifa Sidhpurwala of the Red Hat Security Response Team found a heap-based buffer overflow in JPEG2000 image parsing.
- CVE-2012-3535
Huzaifa Sidhpurwala of the Red Hat Security Response Team found a heap-based buffer overflow when decoding JPEG2000 images.
For the stable distribution (squeeze), these problems have been fixed in version 1.3+dfsg-4+squeeze1.
For the testing (wheezy) and unstable (sid) distributions, these problems have been fixed in version 1.3+dfsg-4.6.
We recommend that you upgrade your openjpeg packages.
- CVE-2009-5030