MGASA-2014-0005
Dashboard / Vulnerabilities / MGASA-2014-0005
MGASA-2014-0005
Summary: Updated openjpeg package fixes security vulnerabilities
Details: Multiple heap-based buffer overflow flaws were found in OpenJPEG. An attacker could create a specially crafted OpenJPEG image that, when opened, could cause an application using openjpeg to crash or, possibly, execute arbitrary code with the privileges of the user running the application (CVE-2013-6045). Multiple denial of service flaws were found in OpenJPEG. An attacker could create a specially crafted OpenJPEG image that, when opened, could cause an application using openjpeg to crash (CVE-2013-1447, CVE-2013-6052, CVE-2013-6053, CVE-2013-6887).
References: https://advisories.mageia.org/MGASA-2014-0005.html, https://bugs.mageia.org/show_bug.cgi?id=11863, http://openwall.com/lists/oss-security/2013/12/04/6, https://rhn.redhat.com/errata/RHSA-2013-1850.html
Affected packages
Package
Name: openjpeg
Purl: pkg:rpm/mageia/openjpeg?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
