Advisories ยป MGASA-2016-0426

Updated openjpeg2 packages fix security vulnerabilities

Publication date: 29 Dec 2016
Modification date: 29 Dec 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-9572 , CVE-2016-9573 , CVE-2016-9580 , CVE-2016-9581

Description

A NULL pointer dereference flaw was found in the way openjpeg decoded
certain input images. Due to a logic error in the code responsible for
decoding the input image, an application using openjpeg to process image
data could crash when processing a crafted image (CVE-2016-9572).

A heap buffer overflow flaw was found in the way openjpeg decompressed
certain input images. Due to an insufficient check in the imagetopnm()
function, an application using openjpeg to process image data could
crash when processing a crafted image (CVE-2016-9573).

An integer overflow vulnerability was found in tiftoimage function
resulting into heap buffer overflow (CVE-2016-9580).

An infinite loop vulnerability in tiftoimage that results into heap
buffer overflow in convert_32s_C1P1 was found (CVE-2016-9581)
                

References

SRPMS

5/core