Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 629668 (CVE-2017-14039) - <media-libs/openjpeg-2.3.0: multiple vulnerabilities
Summary: <media-libs/openjpeg-2.3.0: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2017-14039
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [glsa cve cleanup]
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2017-09-02 14:49 UTC by Aleksandr Wagner (Kivak)
Modified: 2018-07-28 17:55 UTC (History)
1 user (show)

See Also:
Package list:
media-libs/openjpeg-2.3.0
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-09-02 14:49:16 UTC
From $URL:

A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.

Upstream bug:

https://github.com/uclouvain/openjpeg/issues/992

Upstream patch:

https://github.com/uclouvain/openjpeg/commit/c535531f03369623b9b833ef41952c62257b507e

References:

https://blogs.gentoo.org/ago/2017/08/28/openjpeg-heap-based-buffer-overflow-in-opj_t2_encode_packet-t2-c/
Comment 1 Agostino Sarubbo gentoo-dev 2017-10-09 13:50:07 UTC
2.3.0 is in tree. It fixes several other vulnerabilities like this:
https://blogs.gentoo.org/ago/2017/08/28/openjpeg-stack-based-buffer-overflow-write-in-pgxtoimage-convert-c/

Can we stabilize?
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2017-10-09 18:02:45 UTC
@ Arches,

please test and mark stable: =media-libs/openjpeg-2.3.0
Comment 3 Sergei Trofimovich (RETIRED) gentoo-dev 2017-10-10 23:05:08 UTC
hppa stable
Comment 4 Manuel Rüger (RETIRED) gentoo-dev 2017-10-11 18:00:57 UTC
Stable on amd64
Comment 5 Thomas Deutschmann (RETIRED) gentoo-dev 2017-10-12 21:19:55 UTC
x86 stable
Comment 6 Sergei Trofimovich (RETIRED) gentoo-dev 2017-10-13 00:15:32 UTC
ia64 stable
Comment 7 Sergei Trofimovich (RETIRED) gentoo-dev 2017-10-13 09:11:05 UTC
ppc/ppc64 stable
Comment 8 Markus Meier gentoo-dev 2017-10-14 06:17:49 UTC
arm stable
Comment 9 Tobias Klausmann (RETIRED) gentoo-dev 2017-10-21 13:26:03 UTC
Stable on alpha.
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2017-10-21 23:57:07 UTC
@maintainers, please clean the vulnerable versions.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2017-10-23 01:40:22 UTC
This issue was resolved and addressed in
 GLSA 201710-26 at https://security.gentoo.org/glsa/201710-26
by GLSA coordinator Aaron Bauman (b-man).
Comment 12 Sergei Trofimovich (RETIRED) gentoo-dev 2018-07-28 17:55:15 UTC
commit 43ba3bc2fbc5d86243cf8c68ff825eaa34bd1146
Author: Mart Raudsepp <leio@gentoo.org>
Date:   Sat Mar 3 14:14:07 2018 +0200

    media-libs/openjpeg-2.3.0: arm64 stable