From bd7908c6630f38067350d396ac5d18c3cc2434a0 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sun, 29 Oct 2017 11:22:34 +0000 Subject: gentoo resync : 29.10.2017 --- metadata/glsa/glsa-201710-26.xml | 114 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 114 insertions(+) create mode 100644 metadata/glsa/glsa-201710-26.xml (limited to 'metadata/glsa/glsa-201710-26.xml') diff --git a/metadata/glsa/glsa-201710-26.xml b/metadata/glsa/glsa-201710-26.xml new file mode 100644 index 000000000000..ecbdd99167f3 --- /dev/null +++ b/metadata/glsa/glsa-201710-26.xml @@ -0,0 +1,114 @@ + + + + OpenJPEG: Multiple vulnerabilities + Multiple vulnerabilities have been found in OpenJPEG, the worst of + which may allow remote attackers to execute arbitrary code. + + openjpeg + 2017-10-23 + 2017-10-23: 1 + 602180 + 606618 + 628504 + 629372 + 629668 + 630120 + remote + + + 2.3.0 + 2.3.0 + + + +

OpenJPEG is an open-source JPEG 2000 library.

+
+ +

Multiple vulnerabilities have been discovered in OpenJPEG. Please review + the references below for details. +

+ +
+ +

A remote attacker, via a crafted BMP, PDF, or j2k document, could + execute arbitrary code, cause a Denial of Service condition, or have + other unspecified impacts. +

+
+ +

There is no known workaround at this time.

+
+ +

All OpenJPEG users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-libs/openjpeg-2.3.0:2" + +
+ + + CVE-2016-10504 + + + CVE-2016-10505 + + + CVE-2016-10506 + + + CVE-2016-10507 + + + CVE-2016-1626 + + + CVE-2016-1628 + + + CVE-2016-9112 + + + CVE-2016-9113 + + + CVE-2016-9114 + + + CVE-2016-9115 + + + CVE-2016-9116 + + + CVE-2016-9117 + + + CVE-2016-9118 + + + CVE-2016-9572 + + + CVE-2016-9573 + + + CVE-2016-9580 + + + CVE-2016-9581 + + + CVE-2017-12982 + + + CVE-2017-14039 + + + CVE-2017-14164 + + + b-man + chrisadr +
-- cgit v1.2.3