Oval Definition:oval:com.redhat.rhsa:def:20170838
Revision Date:2017-03-23Version:639
Title:RHSA-2017:0838: openjpeg security update (Moderate)
Description:OpenJPEG is an open source library for reading and writing image files in JPEG2000 format.

Security Fix(es):

  • Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in OpenJPEG. A specially crafted JPEG2000 image could cause an application using OpenJPEG to crash or, potentially, execute arbitrary code. (CVE-2016-5139, CVE-2016-5158, CVE-2016-5159, CVE-2016-7163)

  • An out-of-bounds read vulnerability was found in OpenJPEG, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap. (CVE-2016-9573)

  • A heap-based buffer overflow vulnerability was found in OpenJPEG. A specially crafted JPEG2000 image, when read by an application using OpenJPEG, could cause the application to crash or, potentially, execute arbitrary code. (CVE-2016-9675)

    Red Hat would like to thank Liu Bingchang (IIE) for reporting CVE-2016-9573. The CVE-2016-9675 issue was discovered by Doran Moppert (Red Hat Product Security).
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-5139
    CVE-2016-5158
    CVE-2016-5159
    CVE-2016-7163
    CVE-2016-9573
    CVE-2016-9675
    RHSA-2017:0838
    RHSA-2017:0838-00
    RHSA-2017:0838-01
    RHSA-2017:0838-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • openjpeg is earlier than 0:1.5.1-16.el7_3
  • AND openjpeg is signed with Red Hat redhatrelease2 key
  • openjpeg-devel is earlier than 0:1.5.1-16.el7_3
  • AND openjpeg-devel is signed with Red Hat redhatrelease2 key
  • openjpeg-libs is earlier than 0:1.5.1-16.el7_3
  • AND openjpeg-libs is signed with Red Hat redhatrelease2 key
  • BACK