Oval Definition:oval:com.redhat.rhsa:def:20170559
Revision Date:2017-03-20Version:642
Title:RHSA-2017:0559: openjpeg security update (Moderate)
Description:OpenJPEG is an open source library for reading and writing image files in JPEG2000 format.

Security Fix(es):

  • Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in OpenJPEG. A specially crafted JPEG2000 image could cause an application using OpenJPEG to crash or, potentially, execute arbitrary code. (CVE-2016-5139, CVE-2016-5158, CVE-2016-5159, CVE-2016-7163)

  • A vulnerability was found in the patch for CVE-2013-6045 for OpenJPEG. A specially crafted JPEG2000 image, when read by an application using OpenJPEG, could cause heap-based buffer overflows leading to a crash or, potentially, arbitrary code execution. (CVE-2016-9675)

    The CVE-2016-9675 issue was discovered by Doran Moppert (Red Hat Product Security).
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-5139
    CVE-2016-5158
    CVE-2016-5159
    CVE-2016-7163
    CVE-2016-9675
    RHSA-2017:0559
    RHSA-2017:0559-00
    RHSA-2017:0559-01
    RHSA-2017:0559-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • openjpeg is earlier than 0:1.3-16.el6_8
  • AND openjpeg is signed with Red Hat redhatrelease2 key
  • openjpeg-devel is earlier than 0:1.3-16.el6_8
  • AND openjpeg-devel is signed with Red Hat redhatrelease2 key
  • openjpeg-libs is earlier than 0:1.3-16.el6_8
  • AND openjpeg-libs is signed with Red Hat redhatrelease2 key
  • BACK