[3.9] openjpeg: Multiple vulnerabilities (CVE-2017-17480, CVE-2018-18088)
CVE-2018-18088: NULL pointer dereference in the imagetopnm function of jp2/convert.c
A flaw was found in OpenJPEG 2.3.0. A NULL pointer dereference for “red”
in the
imagetopnm function of jp2/convert.c
References:
https://github.com/uclouvain/openjpeg/issues/1152
https://nvd.nist.gov/vuln/detail/CVE-2018-18088
Patch:
https://github.com/uclouvain/openjpeg/commit/cab352e249ed3372dd9355c85e837613fff98fa2
CVE-2017-17480: Stack-buffer overflow in the pgxtovolume function
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the
pgxtovolume function in jp3d/convert.c. The vulnerability
causes an out-of-bounds write, which may lead to remote denial of
service or possibly remote code execution.
References:
https://github.com/uclouvain/openjpeg/issues/1044
https://security-tracker.debian.org/tracker/CVE-2017-17480
Patch:
https://github.com/uclouvain/openjpeg/commit/0bc90e4062a5f9258c91eca018c019b179066c62
(from redmine: issue id 9679, created on 2018-11-22, closed on 2018-11-26)
- Relations:
- parent #9678 (closed)
- Changesets:
- Revision 5b27b635 by Natanael Copa on 2018-11-22T15:57:59Z:
main/openjpeg: security fix for CVE-2017-17480
also remove unused patches
fixes #9679