Publishing details

Changelog

openjpeg2 (2.3.1-1ubuntu4) focal; urgency=medium

  * SECURITY UPDATE: denial of service via excessive iteration
    - debian/patches/CVE-2019-12973-1.patch: detect invalid file dimensions
      early in src/bin/jp2/convertbmp.c.
    - debian/patches/CVE-2019-12973-2.patch: avoid potential infinite loop
      in src/bin/jp2/convertbmp.c.
    - CVE-2019-12973
  * SECURITY UPDATE: heap overflow in opj_t1_clbl_decode_processor
    - debian/patches/CVE-2020-6851.patch: reject images whose
      coordinates are beyond INT_MAX in src/lib/openjp2/j2k.c.
    - CVE-2020-6851
  * SECURITY UPDATE: another heap overflow in opj_t1_clbl_decode_processor
    - debian/patches/CVE-2020-8112.patch: avoid integer overflow in
      src/lib/openjp2/tcd.c.
    - CVE-2020-8112

 -- Marc Deslauriers <email address hidden>  Wed, 19 Feb 2020 09:52:00 -0500

Available diffs

Builds

Package files