** Changed in: openjpeg (Ubuntu)
   Importance: Undecided => Medium

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to openjpeg in Ubuntu.
https://bugs.launchpad.net/bugs/1023259

Title:
  (CVE-2012-3358) CVE-2012-3358 openjpeg: heap-based buffer overflow
  when processing JPEG2000 image files

Status in openjpeg package in Ubuntu:
  Fix Released
Status in openjpeg package in Debian:
  Fix Released
Status in openjpeg package in Fedora:
  Fix Released

Bug description:
  A heap-based buffer overflow was found in the way OpenJPEG, an
  open-source JPEG 2000 codec written in C language, performed parsing of
  JPEG2000 having certain number of tiles and tilesizes. A remote
  attacker could provide a specially crafted JPEG 2000 file, which when
  opened in an application linked against openjpeg would lead to that
  application crash, or, potentially arbitrary code execution with the
  privileges of the user running the application.

  Upstream patch:
  http://code.google.com/p/openjpeg/source/detail?r=1727

  References:
  https://bugzilla.redhat.com/show_bug.cgi?id=835767
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681075

  This issue has been assigned CVE-2012-3358

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openjpeg/+bug/1023259/+subscriptions

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to