Debian Security Advisory

DSA-3665-1 openjpeg2 -- security update

Date Reported:
11 Sep 2016
Affected Packages:
openjpeg2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-6581, CVE-2015-8871, CVE-2016-1924, CVE-2016-7163.
More information:

Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of service or the execution of arbitrary code if a malformed JPEG 2000 file is processed.

For the stable distribution (jessie), these problems have been fixed in version 2.1.0-2+deb8u1.

We recommend that you upgrade your openjpeg2 packages.