Debian Security Advisory

DLA-2796-1 jbig2dec -- LTS security update

Date Reported:
28 Oct 2021
Affected Packages:
jbig2dec
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-9216, CVE-2020-12268.
More information:

Two issues have been found in jbig2dec, a JBIG2 decoder library. One issue is related to an overflow with a crafted image file. The other is related to a NULL pointer dereference.

For Debian 9 stretch, these problems have been fixed in version 0.13-4.1+deb9u1.

We recommend that you upgrade your jbig2dec packages.

For the detailed security status of jbig2dec please refer to its security tracker page at: https://security-tracker.debian.org/tracker/jbig2dec

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS