[Pkg-phototools-devel] Bug#731237: openjpeg: CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 CVE-2013-6054

2013-12-03 Thread Salvatore Bonaccorso
Package: openjpeg Severity: grave Tags: security upstream patch Hi This is to track the issues released with DSA-2808-1 for openjpeg in the BTS. See http://lists.debian.org/debian-security-announce/2013/msg00222.html http://www.debian.org/security/2013/dsa-2808 Regards, Salvatore ___

[Pkg-phototools-devel] Bug#743372: openjpeg: CVE-2014-0158: Heap-based buffer overflow in JPEG2000 image tile decoder

2014-04-02 Thread Salvatore Bonaccorso
Source: openjpeg Severity: grave Tags: security upstream Hi, the following vulnerability was published for openjpeg. CVE-2014-0158[0]: Heap-based buffer overflow in JPEG2000 image tile decoder More information are on the Red Hat bugzilla[1]. If you fix the vulnerability please also make sure t

[Pkg-phototools-devel] Bug#786792: darktable: CVE-2015-3885: input sanitization flaw leading to buffer overflow

2015-05-25 Thread Salvatore Bonaccorso
Source: darktable Version: 1.0.4-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for darktable. CVE-2015-3885[0]: | Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier | allows remote attackers to cause a denial of service (crash) vi

[Pkg-phototools-devel] Bug#800149: openjpeg2: Use-after-free in opj_j2k_write_mco

2015-09-27 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: important Tags: security upstream patch fixed-upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/563 Hi A use-after-free vulnerability was found in openjpeg2, see http://www.openwall.com/lists/oss-security/2015/09/15/4 for the correspondi

[Pkg-phototools-devel] Bug#801700: optipng: CVE-2015-7802: Buffer overflow in global memory

2015-10-13 Thread Salvatore Bonaccorso
Source: optipng Version: 0.7.5-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for optipng. CVE-2015-7802[0]: Buffer overflow in global memory If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) i

[Pkg-phototools-devel] Bug#820068: optipng: CVE-2016-2191: Invalid write while processing delta escapes without any boundary checking

2016-04-05 Thread Salvatore Bonaccorso
Source: optipng Version: 0.6.4-1 Severity: important Tags: security upstream fixed-upstream Forwarded: https://sourceforge.net/p/optipng/bugs/59/ Hi, the following vulnerability was published for optipng and is fixed in 0.7.6 upstream. CVE-2016-2191[0]: Invalid write while processing delta escap

[Pkg-phototools-devel] Bug#820068: optipng: diff for NMU version 0.7.5-1.1

2016-04-07 Thread Salvatore Bonaccorso
+1,12 @@ +optipng (0.7.5-1.1) unstable; urgency=high + + * Non-maintainer upload. + * CVE-2016-2191: Invalid write while processing delta escapes without +any boundary checking (Patch from Moritz Muehlenhoff from the jessie- +security upload) (Closes: #820068) + + -- Salvatore Bonaccorso

[Pkg-phototools-devel] Bug#820068: optipng: diff for NMU version 0.7.5-1.1

2016-04-08 Thread Salvatore Bonaccorso
Hi The used patch took into account as well the fixed from upstream bugs 56 and 57, which correspond to CVE-2016-3981 and CVE-2016-3982. At the time of writing those two CVEs were not yet assigned. So once accepted into the archive, I will update as well the information for those CVEs. Regards,

[Pkg-phototools-devel] Bug#800149: openjpeg2: Use-after-free in opj_j2k_write_mco

2016-05-12 Thread Salvatore Bonaccorso
Control: retitle -1 openjpeg2: CVE-2015-8871: Use-after-free in opj_j2k_write_mco Hi, On Sun, Sep 27, 2015 at 01:54:25PM +0200, Salvatore Bonaccorso wrote: > Source: openjpeg2 > Version: 2.1.0-2 > Severity: important > Tags: security upstream patch fixed-upstream > Forwarded: htt

[Pkg-phototools-devel] Bug#831814: lepton: CVE-2016-6234 CVE-2016-6235 CVE-2016-6236 CVE-2016-6237 CVE-2016-6238

2016-07-19 Thread Salvatore Bonaccorso
Source: lepton Version: 1.0-2 Severity: grave Tags: security upstream Justification: user security hole Hi, Multiple issues were found in lepton. The CVE request was at http://www.openwall.com/lists/oss-security/2016/07/17/1 referencing https://github.com/dropbox/lepton/issues/26 (note to compile

[Pkg-phototools-devel] Bug#837604: openjpeg2: CVE-2016-7163: Integer overflow in opj_pi_create_decode

2016-09-12 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: grave Tags: security upstream patch Control: fixed -1 2.1.0-2+deb8u1 Hi, the following vulnerability was published for openjpeg2. CVE-2016-7163[0]: Integer overflow in opj_pi_create_decode If you fix the vulnerability please also make sure to include

[Pkg-phototools-devel] Bug#844552: openjpeg2: CVE-2016-9113

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/856 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9113[0]: | There is a NULL pointer dereference in function imagetobmp of | convertbmp.c

[Pkg-phototools-devel] Bug#844551: openjpeg2: CVE-2016-9112

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/855 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9112[0]: | Floating Point Exception (aka FPE or divide by zero) in | opj_pi_next_cprl f

[Pkg-phototools-devel] Bug#844554: openjpeg2: CVE-2016-9115

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/858 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9115[0]: | Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in | Open

[Pkg-phototools-devel] Bug#844555: openjpeg2: CVE-2016-9116

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/859 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9116[0]: | NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in | OpenJ

[Pkg-phototools-devel] Bug#844553: openjpeg2: CVE-2016-9114

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/857 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9114[0]: | There is a NULL Pointer Access in function imagetopnm of | convert.c:1943(jp

[Pkg-phototools-devel] Bug#844557: openjpeg2: CVE-2016-9118

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/861 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9118[0]: | Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of | convert.c

[Pkg-phototools-devel] Bug#844556: openjpeg2: CVE-2016-9117

2016-11-16 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/860 Hi, the following vulnerability was published for openjpeg2. CVE-2016-9117[0]: | NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in | OpenJ

[Pkg-phototools-devel] Bug#851422: openjpeg2: CVE-2016-9572 CVE-2016-9573

2017-01-14 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: grave Tags: security upstream patch Justification: user security hole Forwarded: https://github.com/uclouvain/openjpeg/issues/863 Control: fixed -1 2.1.0-2+deb8u2 Hi, the following vulnerabilities were published for openjpeg2. Filling it as RC severity

[Pkg-phototools-devel] Bug#851422: openjpeg2: diff for NMU version 2.1.2-1.1

2017-01-22 Thread Salvatore Bonaccorso
-2016-9572: NULL pointer dereference in input decoding +CVE-2016-9573: Heap out-of-bounds read due to insufficient check in +imagetopnm(). (Closes: #851422) + + -- Salvatore Bonaccorso Sun, 22 Jan 2017 14:18:13 +0100 + openjpeg2 (2.1.2-1) unstable; urgency=medium * New upstream. C

[Pkg-phototools-devel] Bug#859714: lepton: CVE-2017-7448

2017-04-06 Thread Salvatore Bonaccorso
Source: lepton Version: 1.2.1-2 Severity: important Tags: security upstream patch Forwarded: https://github.com/dropbox/lepton/issues/86 Hi, the following vulnerability was published for lepton. CVE-2017-7448[0]: | The allocate_channel_framebuffer function in uncompressed_components.hh | in Drop

[Pkg-phototools-devel] Bug#860367: feh: CVE-2017-7875

2017-04-15 Thread Salvatore Bonaccorso
Source: feh Version: 2.12-1 Severity: normal Tags: upstream security patch fixed-upstream Hi, the following vulnerability was published for fehl. CVE-2017-7875[0]: | In wallpaper.c in feh before v2.18.3, if a malicious client pretends to | be the E17 window manager, it is possible to trigger an

[Pkg-phototools-devel] Bug#862446: lepton: CVE-2017-8891

2017-05-12 Thread Salvatore Bonaccorso
Source: lepton Version: 1.2.1-2 Severity: important Tags: upstream security Forwarded: https://github.com/dropbox/lepton/issues/87 Hi, the following vulnerability was published for lepton. CVE-2017-8891[0]: | Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a | malformed lepton f

[Pkg-phototools-devel] Bug#873022: libexif: CVE-2016-6328: Integer overflow in parsing MNOTE entry data of the input file

2017-08-23 Thread Salvatore Bonaccorso
Source: libexif Version: 0.6.21-2 Severity: important Tags: security patch upstream Hi, the following vulnerability was published for libexif. CVE-2016-6328[0]: |Integer overflow in parsing MNOTE entry data of the input file If you fix the vulnerability please also make sure to include the CVE

[Pkg-phototools-devel] Bug#874113: openjpeg2: CVE-2016-10504: Heap-based buffer over-write in in opj_mqc_byteout function of mqc.c

2017-09-03 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1.1 Severity: important Tags: security upstream patch Forwarded: https://github.com/uclouvain/openjpeg/issues/835 Hi, the following vulnerability was published for openjpeg2. CVE-2016-10504[0]: | Heap-based buffer overflow vulnerability in the opj_mqc_byteout | f

[Pkg-phototools-devel] Bug#874115: openjpeg2: CVE-2017-14041: Stack-based buffer over-write in pgxtoimage function in bin/jp2/convert.c

2017-09-03 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: grave Tags: upstream patch security Forwarded: https://github.com/uclouvain/openjpeg/issues/997 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14041[0]: | A stack-based buffer overflow was discovered in the pgxtoimage function |

[Pkg-phototools-devel] Bug#874117: openjpeg2: CVE-2017-14040: invalid memory write in tgatoimage

2017-09-03 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: important Tags: patch security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/995 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14040[0]: | An invalid write access was discovered in bin/jp2/convert.c in OpenJP

[Pkg-phototools-devel] Bug#874118: openjpeg2: CVE-2017-14039: Heap-based buffer overflow in opj_t2_encode_packet function in lib/openjp2/t2.c

2017-09-03 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-2 Severity: important Tags: patch upstream security Forwarded: https://github.com/uclouvain/openjpeg/issues/992 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14039[0]: | A heap-based buffer overflow was discovered in the opj_t2_encode_pack

[Pkg-phototools-devel] Bug#874430: openjpeg2: CVE-2017-14151: heap-based buffer overflow in opj_mqc_flush

2017-09-05 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1.3 Severity: grave Tags: security upstream patch Forwarded: https://github.com/uclouvain/openjpeg/issues/982 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14151[0]: | An off-by-one error was discovered in | opj_tcd_code_block_enc_allocate

[Pkg-phototools-devel] Bug#874431: openjpeg2: CVE-2017-14152: heap-based buffer overflow in opj_write_bytes_LE

2017-09-05 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.2-1.3 Severity: grave Tags: upstream patch security Forwarded: https://github.com/uclouvain/openjpeg/issues/985 Hi, the following vulnerability was published for openjpeg2. CVE-2017-14152[0]: | A mishandled zero case was discovered in opj_j2k_set_cinema_parameters

[Pkg-phototools-devel] Bug#874431: openjpeg2: CVE-2017-14152: heap-based buffer overflow in opj_write_bytes_LE

2017-09-06 Thread Salvatore Bonaccorso
On Wed, Sep 06, 2017 at 06:58:36AM +0200, Salvatore Bonaccorso wrote: > Source: openjpeg2 > Version: 2.1.2-1.3 > Severity: grave > Tags: upstream patch security > Forwarded: https://github.com/uclouvain/openjpeg/issues/985 > > Hi, > > the following vulnerability

[Pkg-phototools-devel] Bug#876466: libexif: CVE-2017-7544: Out-of-bounds heap read in exif_data_save_data_entry function

2017-09-22 Thread Salvatore Bonaccorso
Source: libexif Version: 0.6.21-2 Severity: important Tags: security patch upstream Forwarded: https://sourceforge.net/p/libexif/bugs/130/ Hi, the following vulnerability was published for libexif. CVE-2017-7544[0]: | libexif through 0.6.21 is vulnerable to out-of-bounds heap read | vulnerabilit

[Pkg-phototools-devel] Bug#876535: openjpeg2: Incoorporate lost changelogs (and possibly changes) for NMUs 2.1.2-1.1, 2.1.2-1.2 and 2.1.2-1.3

2017-09-23 Thread Salvatore Bonaccorso
d due to insufficient check in -imagetopnm(). (Closes: #851422) - - -- Salvatore Bonaccorso Sun, 22 Jan 2017 14:18:13 +0100 + -- Mathieu Malaterre Fri, 22 Sep 2017 21:51:36 +0200 openjpeg2 (2.1.2-1) unstable; urgency=medium cut-cut-cut-cut-cut---

[Pkg-phototools-devel] Bug#876535: openjpeg2: Incoorporate lost changelogs (and possibly changes) for NMUs 2.1.2-1.1, 2.1.2-1.2 and 2.1.2-1.3

2017-09-25 Thread Salvatore Bonaccorso
Hi Mathieu, On Mon, Sep 25, 2017 at 10:12:31AM +0200, Mathieu Malaterre wrote: > Control: tags -1 pending > > Hi Salvatore, > > On Sat, Sep 23, 2017 at 1:59 PM, Salvatore Bonaccorso > wrote: > > Source: openjpeg2 > > Version: 2.2.0-1 > > Severity: normal &

[Pkg-phototools-devel] Bug#877352: openexr:CVE-2017-12596

2017-09-30 Thread Salvatore Bonaccorso
Source: openexr Version: 2.2.0-11.1 Severity: important Tags: upstream security Forwarded: https://github.com/openexr/openexr/issues/238 Hi, the following vulnerability was published for openexr, filling this bug to track the upstream issue at [1]. CVE-2017-12596[0]: | In OpenEXR 2.2.0, a crafte

[Pkg-phototools-devel] Bug#878551: openexr: CVE-2017-14988

2017-10-14 Thread Salvatore Bonaccorso
Source: openexr Version: 2.2.0-11 Severity: important Tags: security upstream Forwarded: https://github.com/openexr/openexr/issues/248 Hi, the following vulnerability was published for openexr. CVE-2017-14988[0]: | Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote | attacke

[Pkg-phototools-devel] Bug#874118: CVE-2017-14039: Heap-based buffer overflow in opj_t2_encode_packet function in lib/openjp2/t2.c

2017-10-16 Thread Salvatore Bonaccorso
Hello Mathieu, On Mon, Oct 16, 2017 at 06:12:30PM +0200, Mathieu Malaterre wrote: > Control: severity -1 important > > While I understand the this generic heap based buffer overflow ought > to be fixed in Debian stable, I fail to see why it is marked as > affecting stretch. [...] In my initial

[Pkg-phototools-devel] Bug#882032: optipng: CVE-2017-1000229: Integer Overflow Bug while parsing TIFF input file

2017-11-17 Thread Salvatore Bonaccorso
Source: optipng Version: 0.7.6-1 Severity: important Tags: security upstream Forwarded: https://sourceforge.net/p/optipng/bugs/65/ Hi, the following vulnerability was published for optipng. CVE-2017-1000229[0]: | Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 | allows an

[Pkg-phototools-devel] Bug#878839: optipng: diff for NMU version 0.7.6-1.1

2017-12-07 Thread Salvatore Bonaccorso
event integer overflow in minitiff_read_info() (CVE-2017-1000229) +(Closes: #882032) + * gifread: Detect indirect circular dependencies in LZW tables +(CVE-2017-16938) (Closes: #878839) + + -- Salvatore Bonaccorso Thu, 07 Dec 2017 20:43:29 +0100 + optipng (0.7.6-1) unstable; urgency=m

[Pkg-phototools-devel] Bug#878839: optipng: moved to delayed/0

2017-12-08 Thread Salvatore Bonaccorso
Hi Emmanuel I perfectly realize it's not conforming to the NMU rules, so if that made you unhappy I apologies for it. I moved the optipng upload from delayed/5 to delayed/0 since was planing a security update, and the point release happening this weekend would imply stretch-version < sid-version.

[Pkg-phototools-devel] Bug#884738: openjpeg2: CVE-2017-17480: stack-based buffer overflow in pgxtovolume function in jp3d/convert.c

2017-12-18 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.1.0-1 Severity: grave Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1044 Hi, the following vulnerability was published for openjpeg2. CVE-2017-17480[0]: | In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the | pgxto

[Pkg-phototools-devel] Bug#888533: openjpeg2: CVE-2018-5785: integer overflow in opj_j2k_setup_encoder function in openjp2/j2k.c

2018-01-27 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.3.0-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1057 Hi, the following vulnerability was published for openjpeg2. CVE-2018-5785[0]: | In OpenJPEG 2.3.0, there is an integer overflow caused by an | out-of-bound

[Pkg-phototools-devel] Bug#888532: openjpeg2: CVE-2018-5727: nteger overflow in opj_t1_encode_cblks in src/lib/openjp2/t1.c

2018-01-27 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.3.0-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1053 Hi, the following vulnerability was published for openjpeg2. CVE-2018-5727[0]: | In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the | opj_

[Pkg-phototools-devel] Bug#889683: openjpeg2: CVE-2018-6616: Excessive Iteration in opj_t1_encode_cblks

2018-02-05 Thread Salvatore Bonaccorso
Source: openjpeg2 Version: 2.3.0-1 Severity: important Tags: security upstream Forwarded: https://github.com/uclouvain/openjpeg/issues/1059 Hi, the following vulnerability was published for openjpeg2. CVE-2018-6616[0]: | In OpenJPEG 2.3.0, there is excessive iteration in the | opj_t1_encode_cblk