Debian Security Advisory

DSA-3768-1 openjpeg2 -- security update

Date Reported:
20 Jan 2017
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2016-5159, CVE-2016-8332, CVE-2016-9572, CVE-2016-9573.
More information:

Multiple vulnerabilities in OpenJPEG, a JPEG 2000 image compression / decompression library, may result in denial of service or the execution of arbitrary code if a malformed JPEG 2000 file is processed.

For the stable distribution (jessie), these problems have been fixed in version 2.1.0-2+deb8u2.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your openjpeg2 packages.