Summary: | <media-libs/libjpeg-turbo-3.0.0: buffer overflow in lossless 12-bit image parsing | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | CONFIRMED --- | ||
Severity: | normal | CC: | codec |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | A3 [glsa?] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 913822 | ||
Bug Blocks: |
Description
John Helmert III
2023-05-29 20:37:15 UTC
I don't get why, but we don't seem to have jdlossls.c in our /var/tmp/portage/media-libs/libjpeg-turbo-2.1.5.1-r1/work/libjpeg-turbo-2.1.5.1. Maybe I'm too tired :) The 3.0.0 release notes mention this, but it's currently unkw'd because of test failures: commit 626886cfd7f73d2440495ac1b8613b0eff27dbfa Author: Sam James <sam@gentoo.org> Date: Mon Jul 3 21:38:15 2023 +0100 media-libs/libjpeg-turbo: add 3.0.0 (unkeyworded) Unkeyworded because of test failures. Signed-off-by: Sam James <sam@gentoo.org> |