GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Tue Jan 26, 2021 7:26 am Post subject: [ GLSA 202101-29 ] OpenJPEG |
|
|
Gentoo Linux Security Advisory
Title: OpenJPEG: Multiple vulnerabilities (GLSA 202101-29)
Severity: normal
Exploitable: remote
Date: 2021-01-26
Bug(s): #711260, #718918
ID: 202101-29
Synopsis
Multiple vulnerabilities have been found in OpenJPEG, the worst of
which could result in the arbitrary execution of code.
Background
OpenJPEG is an open-source JPEG 2000 library.
Affected Packages
Package: media-libs/openjpeg
Vulnerable: < 2.4.0
Vulnerable: < 1.5.2-r1
Unaffected: >= 2.4.0
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in OpenJPEG. Please review
the CVE identifiers referenced below for details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All OpenJPEG 2 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/openjpeg-2.4.0:2"
| Gentoo has discontinued support OpenJPEG 1.x and any dependent packages
should now be using OpenJPEG 2 or have dropped support for the library.
We recommend that users unmerge OpenJPEG 1.x:
Code: | # emerge --unmerge "media-libs/openjpeg:1"
|
References
CVE-2018-21010
CVE-2019-12973
CVE-2020-15389
CVE-2020-27814
CVE-2020-27841
CVE-2020-27842
CVE-2020-27843
CVE-2020-27844
CVE-2020-27845 |
|