Debian Security Advisory
DLA-2796-1 jbig2dec -- LTS security update
- Date Reported:
- 28 Oct 2021
- Affected Packages:
- jbig2dec
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-9216, CVE-2020-12268.
- More information:
-
Two issues have been found in jbig2dec, a JBIG2 decoder library. One issue is related to an overflow with a crafted image file. The other is related to a NULL pointer dereference.
For Debian 9 stretch, these problems have been fixed in version 0.13-4.1+deb9u1.
We recommend that you upgrade your jbig2dec packages.
For the detailed security status of jbig2dec please refer to its security tracker page at: https://security-tracker.debian.org/tracker/jbig2dec
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS