Debian Security Advisory
DSA-3768-1 openjpeg2 -- security update
- Date Reported:
- 20 Jan 2017
- Affected Packages:
- openjpeg2
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-5159, CVE-2016-8332, CVE-2016-9572, CVE-2016-9573.
- More information:
-
Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of service or the execution of arbitrary code if a malformed JPEG 2000 file is processed.
For the stable distribution (jessie), these problems have been fixed in version 2.1.0-2+deb8u2.
For the unstable distribution (sid), these problems will be fixed soon.
We recommend that you upgrade your openjpeg2 packages.