Paketname
openjpeg
Datum
2012-10-03
Advisory ID
MDVSA-2012:157
Betroffene Versionen
2011 i586 , 2011 x86_64

Problembeschreibung

A security issue was identified and fixed in openjpeg:

A heap-based buffer overflow was found in the way OpenJPEG, an
open-source JPEG 2000 codec written in C language, performed parsing
of JPEG2000 image files. A remote attacker could provide a specially
crafted JPEG 2000 file, which when opened in an application linked
against openjpeg would lead to that application crash, or, potentially
arbitrary code execution with the privileges of the user running the
application (CVE-2012-3535).

The updated packages have been patched to correct this issue.

Aktualisierte Pakete

2011 i586

 19c2992e75ae2e78054fd86e4f36cbb1  2011/i586/libopenjpeg2-1.3-8.2-mdv2011.0.i586.rpm
 e997019eba2e7dd10bc2a1ceca6f41c5  2011/i586/libopenjpeg-devel-1.3-8.2-mdv2011.0.i586.rpm 
 f515ecbc10f13f83d18a8c5a22c88dc3  2011/SRPMS/openjpeg-1.3-8.2.src.rpm

2011 x86_64

 7f3ede0e993d9b94712d4ef5fd7b2386  2011/x86_64/lib64openjpeg2-1.3-8.2-mdv2011.0.x86_64.rpm
 704f05ff7387e4dd8425446d4459ece9  2011/x86_64/lib64openjpeg-devel-1.3-8.2-mdv2011.0.x86_64.rpm 
 f515ecbc10f13f83d18a8c5a22c88dc3  2011/SRPMS/openjpeg-1.3-8.2.src.rpm

Referenzen