MDVSA-2012:157
- Package name
- openjpeg
- Date
- 2012-10-03
- Advisory ID
- MDVSA-2012:157
- Affected versions
- 2011 i586 , 2011 x86_64
Problem description
A security issue was identified and fixed in openjpeg:
A heap-based buffer overflow was found in the way OpenJPEG, an
open-source JPEG 2000 codec written in C language, performed parsing
of JPEG2000 image files. A remote attacker could provide a specially
crafted JPEG 2000 file, which when opened in an application linked
against openjpeg would lead to that application crash, or, potentially
arbitrary code execution with the privileges of the user running the
application (CVE-2012-3535).
The updated packages have been patched to correct this issue.
Updated packages
2011 i586
19c2992e75ae2e78054fd86e4f36cbb1 2011/i586/libopenjpeg2-1.3-8.2-mdv2011.0.i586.rpm e997019eba2e7dd10bc2a1ceca6f41c5 2011/i586/libopenjpeg-devel-1.3-8.2-mdv2011.0.i586.rpm f515ecbc10f13f83d18a8c5a22c88dc3 2011/SRPMS/openjpeg-1.3-8.2.src.rpm
2011 x86_64
7f3ede0e993d9b94712d4ef5fd7b2386 2011/x86_64/lib64openjpeg2-1.3-8.2-mdv2011.0.x86_64.rpm 704f05ff7387e4dd8425446d4459ece9 2011/x86_64/lib64openjpeg-devel-1.3-8.2-mdv2011.0.x86_64.rpm f515ecbc10f13f83d18a8c5a22c88dc3 2011/SRPMS/openjpeg-1.3-8.2.src.rpm
