DSA-2629-1 openjpeg -- several issues

Related Vulnerabilities: CVE-2009-5030   CVE-2012-3358   CVE-2012-3535  

CVE-2009-5030 Heap memory corruption leading to invalid free when processing certain Gray16 TIFF images. CVE-2012-3358 Huzaifa Sidhpurwala of the Red Hat Security Response Team found a heap-based buffer overflow in JPEG2000 image parsing. CVE-2012-3535 Huzaifa Sidhpurwala of the Red Hat Security Response Team found a heap-based buffer overflow when decoding JPEG2000 images. For the stable distribution (squeeze), these problems have been fixed in version 1.3+dfsg-4+squeeze1. For the testing (wheezy) and unstable (sid) distributions, these problems have been fixed in version 1.3+dfsg-4.6. We recommend that you upgrade your openjpeg packages.

Debian Security Advisory

DSA-2629-1 openjpeg -- several issues

Date Reported:
25 Feb 2013
Affected Packages:
openjpeg
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 672455, Bug 681075, Bug 685970.
In Mitre's CVE dictionary: CVE-2009-5030, CVE-2012-3358, CVE-2012-3535.
More information:
  • CVE-2009-5030

    Heap memory corruption leading to invalid free when processing certain Gray16 TIFF images.

  • CVE-2012-3358

    Huzaifa Sidhpurwala of the Red Hat Security Response Team found a heap-based buffer overflow in JPEG2000 image parsing.

  • CVE-2012-3535

    Huzaifa Sidhpurwala of the Red Hat Security Response Team found a heap-based buffer overflow when decoding JPEG2000 images.

For the stable distribution (squeeze), these problems have been fixed in version 1.3+dfsg-4+squeeze1.

For the testing (wheezy) and unstable (sid) distributions, these problems have been fixed in version 1.3+dfsg-4.6.

We recommend that you upgrade your openjpeg packages.